Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 561-580 of 664 records
Threat Entry Updated 2024-11-21

CVE-2021-24489 - Before 2 Plugin

The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24489

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24754 - Before 2 Plugin

The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue

PLUGIN Before 2

CVE-2021-24754

HIGH CVSS 7.2 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24752 - Before 2 Plugin

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu WordPress plugin before…

PLUGIN Before 2

CVE-2021-24752

MEDIUM CVSS 5.7 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24675 - Before 2 Plugin

The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in user change their avatar via a CSRF attack

PLUGIN Before 2

CVE-2021-24675

MEDIUM CVSS 6.5 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24672 - Before 2 Plugin

The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2021-24672

MEDIUM CVSS 5.4 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24416 - Before 2 Plugin

The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

PLUGIN Before 2

CVE-2021-24416

MEDIUM CVSS 5.4 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24412 - Before 2 Plugin

The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

PLUGIN Before 2

CVE-2021-24412

MEDIUM CVSS 5.4 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24654 - Before 2 Plugin

The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their profile is viewed

PLUGIN Before 2

CVE-2021-24654

MEDIUM CVSS 5.4 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24660 - Before 2 Plugin

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.

PLUGIN Before 2

CVE-2021-24660

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24661 - Before 2 Plugin

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.

PLUGIN Before 2

CVE-2021-24661

MEDIUM CVSS 4.3 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24652 - Before 2 Plugin

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.

PLUGIN Before 2

CVE-2021-24652

MEDIUM CVSS 6.5 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24632 - Before 2 Plugin

The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-24632

MEDIUM CVSS 6.1 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24659 - Before 2 Plugin

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.

PLUGIN Before 2

CVE-2021-24659

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24634 - Before 2 Plugin

The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2021-24634

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24610 - Before 2 Plugin

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

PLUGIN Before 2

CVE-2021-24610

MEDIUM CVSS 4.8 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24569 - Before 2 Plugin

The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as admin to perform Cross-Site Scripting even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24569

MEDIUM CVSS 4.8 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24635 - Before 2 Plugin

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

PLUGIN Before 2

CVE-2021-24635

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24585 - Before 2 Plugin

The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the Even Head of the Timeslot in the response when requesting the event Timeslot data with a user with the edit_posts capability. Combined with the other Unauthorised Event Timeslot Modification issue (https://wpscan.com/reports/submissions/4699/) where an arbitrary user ID can be set, this could allow low privilege users with the edit_posts capability (such as author) to retrieve sensitive User data by iterating over the user_id

PLUGIN Before 2

CVE-2021-24585

MEDIUM CVSS 6.5 2021-09-20
Scroll to top