Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 641-660 of 664 records
Threat Entry Updated 2024-11-21

CVE-2021-24292 - Before 2 Plugin

The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag” parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a ‘save_builder’ request with the “heading_tag” set to “script”, and the actual “title” parameter set to JavaScript to be executed within the script tags added…

PLUGIN Before 2

CVE-2021-24292

MEDIUM CVSS 5.4 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24315 - Before 2 Plugin

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.

PLUGIN Before 2

CVE-2021-24315

MEDIUM CVSS 4.8 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24280 - Before 2 Plugin

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.

PLUGIN Before 2

CVE-2021-24280

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24194 - Before 2 Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Before 2

CVE-2021-24194

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24193 - Before 2 Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Before 2

CVE-2021-24193

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24192 - Before 2 Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Before 2

CVE-2021-24192

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24278 - Before 2 Plugin

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

PLUGIN Before 2

CVE-2021-24278

HIGH CVSS 7.5 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24279 - Before 2 Plugin

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.

PLUGIN Before 2

CVE-2021-24279

MEDIUM CVSS 6.5 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24282 - Before 2 Plugin

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a form, and more.

PLUGIN Before 2

CVE-2021-24282

MEDIUM CVSS 6.3 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24281 - Before 2 Plugin

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.

PLUGIN Before 2

CVE-2021-24281

MEDIUM CVSS 4.3 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24189 - Before 2 Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Before 2

CVE-2021-24189

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24273 - Before 2 Plugin

The “Clever Addons for Elementor” WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 2

CVE-2021-24273

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24267 - Before 2 Plugin

The “All-in-One Addons for Elementor – WidgetKit” WordPress Plugin before 2.3.10 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 2

CVE-2021-24267

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24266 - Before 2 Plugin

The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 2

CVE-2021-24266

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24263 - Before 2 Plugin

The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 2

CVE-2021-24263

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24235 - Before 2 Theme

The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.

THEME Before 2

CVE-2021-24235

MEDIUM CVSS 6.1 2021-04-22
Threat Entry Updated 2024-11-21

CVE-2021-24220 - Before 2 Theme

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken…

THEME Before 2

CVE-2021-24220

CRITICAL CVSS 9.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24213 - Before 2 Plugin

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.

PLUGIN Before 2

CVE-2021-24213

MEDIUM CVSS 6.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24219 - Before 2 Plugin

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, Luxe by…

PLUGIN Before 2

CVE-2021-24219

MEDIUM CVSS 5.3 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24212 - Before 2 Plugin

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

PLUGIN Before 2

CVE-2021-24212

CRITICAL CVSS 9.8 2021-04-05
Scroll to top