Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3,408
Critical199
High721
Medium2,464
Reset
Showing 3341-3360 of 3408 records
Threat Entry Updated 2024-11-21

CVE-2021-25043 - Changeset Plugin

The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2021-25043

MEDIUM CVSS 6.1 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25027 - Changeset Plugin

The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2021-25027

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2025-05-22

CVE-2021-25022 - Changeset Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues

PLUGIN Changeset

CVE-2021-25022

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24973 - Changeset Plugin

The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin

PLUGIN Changeset

CVE-2021-24973

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24963 - Changeset Plugin

The LiteSpeed Cache WordPress plugin before 4.4.4 does not escape the qc_res parameter before outputting it back in the JS code of an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-24963

MEDIUM CVSS 4.8 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24998 - Changeset Plugin

The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographically secure values, and should not be used for cryptographic purposes" according to PHP's documentation.

PLUGIN Changeset

CVE-2021-24998

HIGH CVSS 7.5 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24979 - Changeset Plugin

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Changeset

CVE-2021-24979

MEDIUM CVSS 6.1 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24753 - Changeset Plugin

The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue

PLUGIN Changeset

CVE-2021-24753

HIGH CVSS 7.2 2021-12-27
Threat Entry Updated 2026-03-06

CVE-2021-24750 - Changeset Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

PLUGIN Changeset

CVE-2021-24750

HIGH CVSS 8.8 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-4073 - Changeset Plugin

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

PLUGIN Changeset

CVE-2021-4073

CRITICAL CVSS 9.8 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-24955 - Changeset Plugin

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2021-24955

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24954 - Changeset Plugin

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2021-24954

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24747 - Changeset Plugin

The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_ajax" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly escaped leading to blind and error-based SQL injections.

PLUGIN Changeset

CVE-2021-24747

HIGH CVSS 7.2 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-25041 - Changeset Plugin

The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action

PLUGIN Changeset

CVE-2021-25041

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24935 - Changeset Plugin

The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues

PLUGIN Changeset

CVE-2021-24935

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-42365 - Changeset Plugin

The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the name parameter found in the ~/admin/tables/admin-structure-table.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.15.13. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Changeset

CVE-2021-42365

MEDIUM CVSS 4.8 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24883 - Changeset Plugin

The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

PLUGIN Changeset

CVE-2021-24883

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24842 - Changeset Plugin

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

PLUGIN Changeset

CVE-2021-24842

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24894 - Changeset Plugin

The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page

PLUGIN Changeset

CVE-2021-24894

MEDIUM CVSS 6.5 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24873 - Changeset Plugin

The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Changeset

CVE-2021-24873

MEDIUM CVSS 6.1 2021-11-23
Scroll to top