Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 421-440 of 472 records
Threat Entry Updated 2024-11-21

CVE-2021-24671 - Before 3 Plugin

The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2021-24671

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24741 - Before 3 Plugin

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

PLUGIN Before 3

CVE-2021-24741

CRITICAL CVSS 9.8 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24636 - Before 3 Plugin

The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link

PLUGIN Before 3

CVE-2021-24636

HIGH CVSS 8.1 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24637 - Before 3 Plugin

The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

PLUGIN Before 3

CVE-2021-24637

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24511 - Before 3 Plugin

The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

PLUGIN Before 3

CVE-2021-24511

HIGH CVSS 7.2 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24609 - Before 3 Plugin

The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 3

CVE-2021-24609

MEDIUM CVSS 4.8 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24588 - Before 3 Plugin

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

PLUGIN Before 3

CVE-2021-24588

MEDIUM CVSS 6.1 2021-09-06
Threat Entry Updated 2024-11-21

CVE-2021-24579 - Before 3 Plugin

The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a PHP Object Injection. Even though the plugin did not contain a suitable gadget to fully exploit the issue, other installed plugins on the blog could allow such issue to be exploited and lead to RCE in some cases.

PLUGIN Before 3

CVE-2021-24579

HIGH CVSS 8.8 2021-08-30
Threat Entry Updated 2024-11-21

CVE-2021-24658 - Before 3 Plugin

The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled)

PLUGIN Before 3

CVE-2021-24658

MEDIUM CVSS 4.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24486 - Before 3 Plugin

The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 3

CVE-2021-24486

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24527 - Before 3 Plugin

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.

PLUGIN Before 3

CVE-2021-24527

CRITICAL CVSS 9.8 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24512 - Before 3 Plugin

The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos.

PLUGIN Before 3

CVE-2021-24512

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24522 - Before 3 Plugin

The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.

PLUGIN Before 3

CVE-2021-24522

MEDIUM CVSS 6.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24507 - Before 3 Plugin

The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

PLUGIN Before 3

CVE-2021-24507

CRITICAL CVSS 9.8 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24467 - Before 3 Plugin

The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being used, or using malicious attributions which will be executed in all page with an embed map from the plugin

PLUGIN Before 3

CVE-2021-24467

MEDIUM CVSS 6.5 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24472 - Before 3 Theme

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

THEME Before 3

CVE-2021-24472

CRITICAL CVSS 9.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24483 - Before 3 Plugin

The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Before 3

CVE-2021-24483

HIGH CVSS 7.2 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24470 - Before 3 Plugin

The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24470

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24460 - Before 3 Plugin

The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Before 3

CVE-2021-24460

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24468 - Before 3 Plugin

The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues

PLUGIN Before 3

CVE-2021-24468

MEDIUM CVSS 5.4 2021-08-02
Scroll to top