Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total291
Critical15
High59
Medium208
Reset
Showing 241-260 of 291 records
Threat Entry Updated 2024-11-21

CVE-2021-24900 - Before 4 Plugin

The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 4

CVE-2021-24900

MEDIUM CVSS 4.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25074 - Before 4 Plugin

The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

PLUGIN Before 4

CVE-2021-25074

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25065 - Before 4 Plugin

The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.

PLUGIN Before 4

CVE-2021-25065

MEDIUM CVSS 5.4 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25036 - Before 4 Plugin

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.

PLUGIN Before 4

CVE-2021-25036

HIGH CVSS 8.8 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25037 - Before 4 Plugin

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).

PLUGIN Before 4

CVE-2021-25037

MEDIUM CVSS 6.5 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25023 - Before 4 Plugin

The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_table_name parameter before using it in a SQL statement to convert the related table, leading to an SQL injection

PLUGIN Before 4

CVE-2021-25023

HIGH CVSS 7.2 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25021 - Before 4 Plugin

The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin

PLUGIN Before 4

CVE-2021-25021

MEDIUM CVSS 4.9 2022-01-03
Threat Entry Updated 2025-05-22

CVE-2021-24786 - Before 4 Plugin

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

PLUGIN Before 4

CVE-2021-24786

HIGH CVSS 7.2 2022-01-03
Threat Entry Updated 2025-05-22

CVE-2021-24964 - Before 4 Plugin

The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud servers, allowing attackers to make requests to certain endpoints by using a specific X-Forwarded-For header value. In addition, one of the endpoint could be used to set CSS code if a setting is enabled, which will then be output in some pages without being sanitised and escaped. Combining those two issues, an unauthenticated attacker could put Cross-Site Scripting payloads in pages visited by users.

PLUGIN Before 4

CVE-2021-24964

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25020 - Before 4 Plugin

The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin

PLUGIN Before 4

CVE-2021-25020

MEDIUM CVSS 4.9 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24963 - Before 4 Plugin

The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 4

CVE-2021-24963

MEDIUM CVSS 4.8 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24980 - Before 4 Plugin

The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page

PLUGIN Before 4

CVE-2021-24980

MEDIUM CVSS 6.1 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24988 - Before 4 Plugin

The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscriber to call it and set a malicious payload in the addon parameter.

PLUGIN Before 4

CVE-2021-24988

MEDIUM CVSS 5.4 2021-12-27
Threat Entry Updated 2026-03-06

CVE-2021-24750 - Before 4 Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

PLUGIN Before 4

CVE-2021-24750

HIGH CVSS 8.8 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24951 - Before 4 Plugin

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

PLUGIN Before 4

CVE-2021-24951

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24872 - Before 4 Plugin

The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.

PLUGIN Before 4

CVE-2021-24872

MEDIUM CVSS 6.5 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24871 - Before 4 Plugin

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

PLUGIN Before 4

CVE-2021-24871

MEDIUM CVSS 5.4 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24918 - Before 4 Plugin

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

PLUGIN Before 4

CVE-2021-24918

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24768 - Before 4 Plugin

The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.

PLUGIN Before 4

CVE-2021-24768

MEDIUM CVSS 4.8 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24877 - Before 4 Plugin

The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed

PLUGIN Before 4

CVE-2021-24877

HIGH CVSS 7.2 2021-11-23
Scroll to top