Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total472
Critical34
High97
Medium322
Reset
Showing 461-472 of 472 records
Threat Entry Updated 2024-11-21

CVE-2021-24206 - Before 3 Plugin

In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

PLUGIN Before 3

CVE-2021-24206

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24205 - Before 3 Plugin

In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

PLUGIN Before 3

CVE-2021-24205

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24204 - Before 3 Plugin

In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

PLUGIN Before 3

CVE-2021-24204

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24203 - Before 3 Plugin

In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘text’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.

PLUGIN Before 3

CVE-2021-24203

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24202 - Before 3 Plugin

In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request with this parameter set to ‘script’ and combined with a ‘title’ parameter containing JavaScript, which will then be executed when the saved page is viewed or previewed.

PLUGIN Before 3

CVE-2021-24202

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24201 - Before 3 Plugin

In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘html_tag’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

PLUGIN Before 3

CVE-2021-24201

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24163 - Before 3 Plugin

The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin.

PLUGIN Before 3

CVE-2021-24163

HIGH CVSS 8.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24169 - Before 3 Plugin

This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

PLUGIN Before 3

CVE-2021-24169

MEDIUM CVSS 6.1 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24165 - Before 3 Plugin

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

PLUGIN Before 3

CVE-2021-24165

MEDIUM CVSS 6.1 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24166 - Before 3 Plugin

The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.

PLUGIN Before 3

CVE-2021-24166

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24164 - Before 3 Plugin

In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

PLUGIN Before 3

CVE-2021-24164

MEDIUM CVSS 4.3 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24153 - Before 3 Plugin

A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.

PLUGIN Before 3

CVE-2021-24153

MEDIUM CVSS 5.4 2021-04-05
Scroll to top