Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 381-400 of 472 records
Threat Entry Updated 2024-11-21

CVE-2021-24738 - Before 3 Plugin

The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2021-24738

MEDIUM CVSS 5.4 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24955 - Before 3 Plugin

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24955

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24954 - Before 3 Plugin

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24954

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24932 - Before 3 Plugin

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.

PLUGIN Before 3

CVE-2021-24932

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24747 - Before 3 Plugin

The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_ajax" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly escaped leading to blind and error-based SQL injections.

PLUGIN Before 3

CVE-2021-24747

HIGH CVSS 7.2 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24939 - Before 3 Plugin

The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and rul_logout_url parameter before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24939

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24935 - Before 3 Plugin

The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues

PLUGIN Before 3

CVE-2021-24935

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24714 - Before 3 Plugin

The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2021-24714

MEDIUM CVSS 4.8 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24927 - Before 3 Plugin

The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24927

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24889 - Before 3 Plugin

The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks

PLUGIN Before 3

CVE-2021-24889

HIGH CVSS 7.2 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24860 - Before 3 Plugin

The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue

PLUGIN Before 3

CVE-2021-24860

HIGH CVSS 7.2 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24891 - Before 3 Plugin

The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.

PLUGIN Before 3

CVE-2021-24891

MEDIUM CVSS 6.1 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24875 - Before 3 Plugin

The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24875

MEDIUM CVSS 6.1 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24888 - Before 3 Plugin

The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high privilege users to perform Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2021-24888

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2026-01-23

CVE-2021-24713 - Before 3 Plugin

The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2021-24713

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24850 - Before 3 Plugin

The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by storing the payload/s in another post's custom fields.

PLUGIN Before 3

CVE-2021-24850

MEDIUM CVSS 5.4 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24851 - Before 3 Plugin

The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.

PLUGIN Before 3

CVE-2021-24851

MEDIUM CVSS 4.3 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24804 - Before 3 Plugin

The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user roles can be updated, which could result in site takeover.

PLUGIN Before 3

CVE-2021-24804

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24772 - Before 3 Plugin

The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.

PLUGIN Before 3

CVE-2021-24772

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24829 - Before 3 Plugin

The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue

PLUGIN Before 3

CVE-2021-24829

HIGH CVSS 8.8 2021-11-08
Scroll to top