Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 621-640 of 664 records
Threat Entry Updated 2024-11-21

CVE-2021-24389 - Before 2 Plugin

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

PLUGIN Before 2

CVE-2021-24389

MEDIUM CVSS 6.1 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24376 - Before 2 Plugin

The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload a zip which contained a directory with PHP file in it and then it is not removed from the disk. It is a bypass of CVE-2020-24948 which allows sending a PHP file via the "Import Settings" functionality to achieve Remote Code Execution.

PLUGIN Before 2

CVE-2021-24376

CRITICAL CVSS 9.8 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24377 - Before 2 Plugin

The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.

PLUGIN Before 2

CVE-2021-24377

HIGH CVSS 8.1 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24378 - Before 2 Plugin

The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.

PLUGIN Before 2

CVE-2021-24378

MEDIUM CVSS 4.8 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24361 - Before 2 Plugin

In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.

PLUGIN Before 2

CVE-2021-24361

CRITICAL CVSS 9.8 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24369 - Before 2 Plugin

In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Text input fields were not getting sanitized properly. So it was possible to inject malicious content such as img tags, leading to a Stored Cross-Site Scripting issue which is triggered when the form will be edited, for example when an admin reviews it and could lead to privilege escalation.

PLUGIN Before 2

CVE-2021-24369

MEDIUM CVSS 5.4 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24339 - Before 2 Plugin

The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.

PLUGIN Before 2

CVE-2021-24339

MEDIUM CVSS 5.4 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24338 - Before 2 Plugin

The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Singular Label' field parameter.

PLUGIN Before 2

CVE-2021-24338

MEDIUM CVSS 5.4 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24356 - Before 2 Plugin

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.

PLUGIN Before 2

CVE-2021-24356

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24354 - Before 2 Plugin

A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.

PLUGIN Before 2

CVE-2021-24354

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24353 - Before 2 Plugin

The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.

PLUGIN Before 2

CVE-2021-24353

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24352 - Before 2 Plugin

The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.

PLUGIN Before 2

CVE-2021-24352

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24341 - Before 2 Plugin

When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement, leading to SQL injection.

PLUGIN Before 2

CVE-2021-24341

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24357 - Before 2 Plugin

In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.

PLUGIN Before 2

CVE-2021-24357

MEDIUM CVSS 5.4 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24355 - Before 2 Plugin

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.

PLUGIN Before 2

CVE-2021-24355

MEDIUM CVSS 4.3 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24322 - Before 2 Plugin

The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.

PLUGIN Before 2

CVE-2021-24322

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24297 - Before 2 Theme

The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.

THEME Before 2

CVE-2021-24297

MEDIUM CVSS 6.1 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24306 - Before 2 Plugin

The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site Scripting issue. Knowledge of the targeted username is required to exploit this, and attackers would then need to make the related logged in user open a malicious link.

PLUGIN Before 2

CVE-2021-24306

MEDIUM CVSS 5.4 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24332 - Before 2 Plugin

The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues

PLUGIN Before 2

CVE-2021-24332

MEDIUM CVSS 4.8 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24314 - Before 2 Theme

The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue

THEME Before 2

CVE-2021-24314

CRITICAL CVSS 9.8 2021-05-17
Scroll to top