Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 361-380 of 472 records
Threat Entry Updated 2024-11-21

CVE-2022-0186 - Before 3 Plugin

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard

PLUGIN Before 3

CVE-2022-0186

MEDIUM CVSS 5.4 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0199 - Before 3 Plugin

The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack

PLUGIN Before 3

CVE-2022-0199

MEDIUM CVSS 4.3 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0164 - Before 3 Plugin

The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users

PLUGIN Before 3

CVE-2022-0164

MEDIUM CVSS 4.3 2022-02-21
Threat Entry Updated 2025-03-21

CVE-2021-25069 - Before 3 Plugin

The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-25069

HIGH CVSS 8.8 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-24921 - Before 3 Plugin

The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 3

CVE-2021-24921

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-24874 - Before 3 Plugin

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 3

CVE-2021-24874

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-24928 - Before 3 Plugin

The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_order AJAX action, nor validation and escaping when inserting user data in SQL statement, leading to an SQL injection, and allowing any authenticated user, such as subscriber, to modify arbitrary post content (for example with an XSS payload), as well as exfiltrate any data by copying it to another post.

PLUGIN Before 3

CVE-2021-24928

MEDIUM CVSS 6.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25076 - Before 3 Plugin

The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting

PLUGIN Before 3

CVE-2021-25076

HIGH CVSS 8.8 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24976 - Before 3 Plugin

The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting

PLUGIN Before 3

CVE-2021-24976

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24696 - Before 3 Plugin

The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads

PLUGIN Before 3

CVE-2021-24696

HIGH CVSS 8.8 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24906 - Before 3 Plugin

The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request

PLUGIN Before 3

CVE-2021-24906

HIGH CVSS 7.5 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24923 - Before 3 Plugin

The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24923

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24694 - Before 3 Plugin

The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.

PLUGIN Before 3

CVE-2021-24694

MEDIUM CVSS 5.4 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24893 - Before 3 Plugin

The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.

PLUGIN Before 3

CVE-2021-24893

HIGH CVSS 7.5 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24998 - Before 3 Plugin

The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographically secure values, and should not be used for cryptographic purposes" according to PHP's documentation.

PLUGIN Before 3

CVE-2021-24998

HIGH CVSS 7.5 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24984 - Before 3 Plugin

The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 3

CVE-2021-24984

MEDIUM CVSS 6.1 2021-12-27
Threat Entry Updated 2025-03-21

CVE-2021-24969 - Before 3 Plugin

The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2021-24969

MEDIUM CVSS 5.4 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24797 - Before 3 Plugin

The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

PLUGIN Before 3

CVE-2021-24797

MEDIUM CVSS 6.1 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24849 - Before 3 Plugin

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

PLUGIN Before 3

CVE-2021-24849

CRITICAL CVSS 9.8 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24739 - Before 3 Plugin

The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature

PLUGIN Before 3

CVE-2021-24739

HIGH CVSS 8.1 2021-12-21
Scroll to top