Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3321-3340 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2021-25079 - Changeset Plugin

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

PLUGIN Changeset

CVE-2021-25079

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25078 - Changeset Plugin

The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

PLUGIN Changeset

CVE-2021-25078

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25062 - Changeset Plugin

The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-25062

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25035 - Changeset Plugin

The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-25035

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25031 - Changeset Plugin

The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-25031

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25017 - Changeset Plugin

The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-25017

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25015 - Changeset Plugin

The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2021-25015

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24985 - Changeset Plugin

The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Changeset

CVE-2021-24985

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24976 - Changeset Plugin

The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-24976

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25049 - Changeset Plugin

The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Changeset

CVE-2021-25049

MEDIUM CVSS 4.8 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24865 - Changeset Plugin

The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue

PLUGIN Changeset

CVE-2021-24865

HIGH CVSS 7.2 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24968 - Changeset Plugin

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions

PLUGIN Changeset

CVE-2021-24968

MEDIUM CVSS 5.7 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2022-0236 - Changeset Plugin

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.

PLUGIN Changeset

CVE-2022-0236

HIGH CVSS 7.5 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2021-25036 - Changeset Plugin

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.

PLUGIN Changeset

CVE-2021-25036

HIGH CVSS 8.8 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25037 - Changeset Plugin

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).

PLUGIN Changeset

CVE-2021-25037

MEDIUM CVSS 6.5 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25053 - Changeset Plugin

The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Changeset

CVE-2021-25053

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25052 - Changeset Plugin

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Changeset

CVE-2021-25052

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25051 - Changeset Plugin

The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Changeset

CVE-2021-25051

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25032 - Changeset Plugin

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.

PLUGIN Changeset

CVE-2021-25032

CRITICAL CVSS 9.8 2022-01-10
Scroll to top