Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total135
Critical12
High24
Medium97
Reset
Showing 101-120 of 135 records
Threat Entry Updated 2024-11-21

CVE-2022-0592 - Before 6 Plugin

The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

PLUGIN Before 6

CVE-2022-0592

CRITICAL CVSS 9.8 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2021-25086 - Before 6 Plugin

The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it

PLUGIN Before 6

CVE-2021-25086

MEDIUM CVSS 6.1 2022-05-02
Threat Entry Updated 2024-11-21

CVE-2021-24957 - Before 6 Plugin

The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading to a SQL injection

PLUGIN Before 6

CVE-2021-24957

HIGH CVSS 8.8 2022-04-25
Threat Entry Updated 2024-11-21

CVE-2022-0949 - Before 6 Plugin

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to unauthenticated users, leading to a SQL injection

PLUGIN Before 6

CVE-2022-0949

CRITICAL CVSS 9.8 2022-04-11
Threat Entry Updated 2024-11-21

CVE-2021-25070 - Before 6 Plugin

The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

PLUGIN Before 6

CVE-2021-25070

CRITICAL CVSS 9.8 2022-03-28
Threat Entry Updated 2024-11-21

CVE-2022-0364 - Before 6 Plugin

The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 6

CVE-2022-0364

MEDIUM CVSS 5.4 2022-03-21
Threat Entry Updated 2024-11-21

CVE-2021-25003 - Before 6 Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

PLUGIN Before 6

CVE-2021-25003

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0205 - Before 6 Plugin

The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue

PLUGIN Before 6

CVE-2022-0205

MEDIUM CVSS 5.4 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0360 - Before 6 Plugin

The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues

PLUGIN Before 6

CVE-2022-0360

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25112 - Before 6 Plugin

The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 6

CVE-2021-25112

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2026-01-13

CVE-2021-24977 - Before 6 Plugin

The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to sent arbitrary CSS which will then be processed by the frontend for all users. Due to the lack of sanitisation and escaping in the backend, it could also lead to Stored XSS issues

PLUGIN Before 6

CVE-2021-24977

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0193 - Before 6 Plugin

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 6

CVE-2022-0193

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-24947 - Before 6 Plugin

The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server

PLUGIN Before 6

CVE-2021-24947

MEDIUM CVSS 6.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24985 - Before 6 Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 6

CVE-2021-24985

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25046 - Before 6 Plugin

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.

PLUGIN Before 6

CVE-2021-25046

MEDIUM CVSS 5.4 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-24956 - Before 6 Plugin

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 6

CVE-2021-24956

MEDIUM CVSS 6.1 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24946 - Before 6 Plugin

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

PLUGIN Before 6

CVE-2021-24946

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2026-01-16

CVE-2021-24863 - Before 6 Plugin

The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection

PLUGIN Before 6

CVE-2021-24863

CRITICAL CVSS 9.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24925 - Before 6 Plugin

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 6

CVE-2021-24925

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24748 - Before 6 Plugin

The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues

PLUGIN Before 6

CVE-2021-24748

HIGH CVSS 8.8 2021-11-29
Scroll to top