Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 401-420 of 472 records
Threat Entry Updated 2024-11-21

CVE-2021-24807 - Before 3 Plugin

The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.

PLUGIN Before 3

CVE-2021-24807

MEDIUM CVSS 5.4 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24840 - Before 3 Theme

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

THEME Before 3

CVE-2021-24840

MEDIUM CVSS 5.3 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24816 - Before 3 Plugin

The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.

PLUGIN Before 3

CVE-2021-24816

MEDIUM CVSS 4.3 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24731 - Before 3 Plugin

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

PLUGIN Before 3

CVE-2021-24731

CRITICAL CVSS 9.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24693 - Before 3 Plugin

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious plugin

PLUGIN Before 3

CVE-2021-24693

CRITICAL CVSS 9.0 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24695 - Before 3 Plugin

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames

PLUGIN Before 3

CVE-2021-24695

HIGH CVSS 7.5 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24766 - Before 3 Plugin

The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a CSRF attack

PLUGIN Before 3

CVE-2021-24766

MEDIUM CVSS 6.5 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24697 - Before 3 Plugin

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 3

CVE-2021-24697

MEDIUM CVSS 6.1 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24706 - Before 3 Plugin

The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2021-24706

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24698 - Before 3 Plugin

The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.

PLUGIN Before 3

CVE-2021-24698

MEDIUM CVSS 4.3 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24647 - Before 3 Plugin

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

PLUGIN Before 3

CVE-2021-24647

HIGH CVSS 8.1 2021-11-08
Threat Entry Updated 2025-03-21

CVE-2021-24773 - Before 3 Plugin

The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 3

CVE-2021-24773

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24514 - Before 3 Plugin

The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

PLUGIN Before 3

CVE-2021-24514

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24381 - Before 3 Plugin

The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2021-24381

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24677 - Before 3 Plugin

The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.

PLUGIN Before 3

CVE-2021-24677

MEDIUM CVSS 5.3 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24651 - Before 3 Plugin

The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.

PLUGIN Before 3

CVE-2021-24651

HIGH CVSS 7.5 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24577 - Before 3 Plugin

The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.

PLUGIN Before 3

CVE-2021-24577

MEDIUM CVSS 5.4 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24656 - Before 3 Plugin

The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 3

CVE-2021-24656

MEDIUM CVSS 4.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24678 - Before 3 Plugin

The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2021-24678

MEDIUM CVSS 5.4 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24666 - Before 3 Plugin

The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.

PLUGIN Before 3

CVE-2021-24666

CRITICAL CVSS 9.8 2021-09-27
Scroll to top