Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total153
Critical10
High27
Medium112
Reset
Showing 121-140 of 153 records
Threat Entry Updated 2024-11-21

CVE-2021-25051 - Before 5 Plugin

The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Before 5

CVE-2021-25051

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-24949 - Before 5 Plugin

The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL statement, which could lead to SQL injection

PLUGIN Before 5

CVE-2021-24949

CRITICAL CVSS 9.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-24948 - Before 5 Plugin

The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as private and draft posts

PLUGIN Before 5

CVE-2021-24948

HIGH CVSS 7.5 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-24862 - Before 5 Plugin

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

PLUGIN Before 5

CVE-2021-24862

HIGH CVSS 7.2 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25001 - Before 5 Plugin

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_create_products_xml_result parameter before outputting back in the admin dashboard when the Product XML Feeds module is enabled, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 5

CVE-2021-25001

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25000 - Before 5 Plugin

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter before outputting back in the admin dashboard when the General module is enabled, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 5

CVE-2021-25000

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24999 - Before 5 Plugin

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_notice parameter before outputting it back in the admin dashboard when the Pdf Invoicing module is enabled, leading to a Reflected Cross-Site Scripting

PLUGIN Before 5

CVE-2021-24999

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24973 - Before 5 Plugin

The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin

PLUGIN Before 5

CVE-2021-24973

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24680 - Before 5 Plugin

The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activities/Trip Type and Pricing Category pages, allowing users with a role as low as editor to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disallowed

PLUGIN Before 5

CVE-2021-24680

MEDIUM CVSS 5.4 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24866 - Before 5 Plugin

The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion

PLUGIN Before 5

CVE-2021-24866

CRITICAL CVSS 9.8 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24852 - Before 5 Plugin

The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Before 5

CVE-2021-24852

MEDIUM CVSS 6.5 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24716 - Before 5 Plugin

The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin.

PLUGIN Before 5

CVE-2021-24716

MEDIUM CVSS 5.4 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24608 - Before 5 Plugin

The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 5

CVE-2021-24608

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24485 - Before 5 Plugin

The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Before 5

CVE-2021-24485

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24622 - Before 5 Plugin

The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 5

CVE-2021-24622

MEDIUM CVSS 4.8 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24687 - Before 5 Plugin

The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 5

CVE-2021-24687

MEDIUM CVSS 4.8 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24525 - Before 5 Plugin

The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via shortcode attributes. Note: the plugin is inconsistent in its handling of shortcode attributes; some do escape, most don't, and there are even some attributes that are insecure by design (like [su_button]'s onclick attribute).

PLUGIN Before 5

CVE-2021-24525

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24603 - Before 5 Plugin

The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed

PLUGIN Before 5

CVE-2021-24603

MEDIUM CVSS 5.4 2021-09-06
Threat Entry Updated 2024-12-17

CVE-2021-24561 - Before 5 Plugin

The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue

PLUGIN Before 5

CVE-2021-24561

MEDIUM CVSS 5.4 2021-08-23
Threat Entry Updated 2024-11-21

CVE-2021-24471 - Before 5 Plugin

The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, leading to Stored XSS issues by 1. using w, h, controls, cc_lang, color, language, start, stop, or style parameter of youtube shortcode, 2. by using style, class, rel, target, width, height, or alt parameter of youtube_thumb shortcode, or 3. by embedding a video whose title or description contains XSS payload (if API key is configured).

PLUGIN Before 5

CVE-2021-24471

MEDIUM CVSS 5.4 2021-08-16
Scroll to top