Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 581-600 of 664 records
Threat Entry Updated 2024-11-21

CVE-2021-24584 - Before 2 Plugin

The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be perform via CSRF against a logged in with such capability. In versions before 2.3.19, the lack of sanitisation and escaping in some of the fields, like the descritption could also lead to Stored XSS issues

PLUGIN Before 2

CVE-2021-24584

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24583 - Before 2 Plugin

The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be performed via CSRF against a logged in with such capability

PLUGIN Before 2

CVE-2021-24583

MEDIUM CVSS 4.3 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24728 - Before 2 Plugin

The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.

PLUGIN Before 2

CVE-2021-24728

HIGH CVSS 8.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24726 - Before 2 Plugin

The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue

PLUGIN Before 2

CVE-2021-24726

HIGH CVSS 8.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24724 - Before 2 Plugin

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s

PLUGIN Before 2

CVE-2021-24724

MEDIUM CVSS 5.4 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24725 - Before 2 Plugin

The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments

PLUGIN Before 2

CVE-2021-24725

MEDIUM CVSS 4.3 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24621 - Before 2 Plugin

The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capability is disallowed, which could lead to Stored Cross-Site Scripting issues

PLUGIN Before 2

CVE-2021-24621

MEDIUM CVSS 4.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24508 - Before 2 Plugin

The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.

PLUGIN Before 2

CVE-2021-24508

MEDIUM CVSS 6.1 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24599 - Before 2 Plugin

The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data.

PLUGIN Before 2

CVE-2021-24599

MEDIUM CVSS 6.1 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24601 - Before 2 Plugin

The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24601

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24580 - Before 2 Plugin

The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue

PLUGIN Before 2

CVE-2021-24580

HIGH CVSS 8.8 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24438 - Before 2 Plugin

The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

PLUGIN Before 2

CVE-2021-24438

MEDIUM CVSS 6.1 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24593 - Before 2 Plugin

The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-24593

MEDIUM CVSS 5.4 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24528 - Before 2 Plugin

The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to a stored cross site scripting (XSS) vulnerability. Only users with roles capable of managing plugins can modify the plugin's settings.

PLUGIN Before 2

CVE-2021-24528

MEDIUM CVSS 5.4 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24592 - Before 2 Plugin

The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2021-24592

MEDIUM CVSS 4.8 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24564 - Before 2 Plugin

The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24564

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24574 - Before 2 Plugin

The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24574

MEDIUM CVSS 4.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24524 - Before 2 Plugin

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.

PLUGIN Before 2

CVE-2021-24524

MEDIUM CVSS 4.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24518 - Before 2 Plugin

The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-24518

MEDIUM CVSS 4.8 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24521 - Before 2 Plugin

The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.

PLUGIN Before 2

CVE-2021-24521

HIGH CVSS 7.2 2021-08-09
Scroll to top