Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total291
Critical15
High59
Medium208
Reset
Showing 261-280 of 291 records
Threat Entry Updated 2024-11-21

CVE-2021-24841 - Before 4 Plugin

The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 4

CVE-2021-24841

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24884 - Before 4 Plugin

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attacker to perform arbitrary actions on an affected…

PLUGIN Before 4

CVE-2021-24884

CRITICAL CVSS 9.6 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24702 - Before 4 Plugin

The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred_html capability is disallowed

PLUGIN Before 4

CVE-2021-24702

MEDIUM CVSS 4.8 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24711 - Before 4 Plugin

The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack

PLUGIN Before 4

CVE-2021-24711

HIGH CVSS 8.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24719 - Before 4 Theme

The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.

THEME Before 4

CVE-2021-24719

MEDIUM CVSS 6.1 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24465 - Before 4 Plugin

The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manipulated in a way that could lead to data disclosure and arbitrary objects to be deserialized.

PLUGIN Before 4

CVE-2021-24465

HIGH CVSS 8.1 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24670 - Before 4 Plugin

The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks

PLUGIN Before 4

CVE-2021-24670

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24638 - Before 4 Plugin

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

PLUGIN Before 4

CVE-2021-24638

CRITICAL CVSS 9.1 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24639 - Before 4 Plugin

The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.

PLUGIN Before 4

CVE-2021-24639

HIGH CVSS 8.1 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24657 - Before 4 Plugin

The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.

PLUGIN Before 4

CVE-2021-24657

MEDIUM CVSS 6.1 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24560 - Before 4 Plugin

The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 4

CVE-2021-24560

MEDIUM CVSS 6.1 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24562 - Before 4 Plugin

The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades

PLUGIN Before 4

CVE-2021-24562

HIGH CVSS 7.5 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24533 - Before 4 Plugin

The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontend

PLUGIN Before 4

CVE-2021-24533

MEDIUM CVSS 4.8 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24462 - Before 4 Plugin

The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

PLUGIN Before 4

CVE-2021-24462

HIGH CVSS 8.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24430 - Before 4 Plugin

The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE

PLUGIN Before 4

CVE-2021-24430

HIGH CVSS 7.2 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24370 - Before 4 Plugin

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

PLUGIN Before 4

CVE-2021-24370

CRITICAL CVSS 9.8 2021-06-21
Threat Entry Updated 2025-05-05

CVE-2021-24366 - Before 4 Plugin

The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 4

CVE-2021-24366

MEDIUM CVSS 5.4 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24347 - Before 4 Plugin

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

PLUGIN Before 4

CVE-2021-24347

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24358 - Before 4 Plugin

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.

PLUGIN Before 4

CVE-2021-24358

MEDIUM CVSS 6.1 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24351 - Before 4 Plugin

The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)

PLUGIN Before 4

CVE-2021-24351

MEDIUM CVSS 6.1 2021-06-14
Scroll to top