Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total567
Critical21
High113
Medium423
Reset
Showing 561-567 of 567 records
Threat Entry Updated 2024-11-21

CVE-2021-24247 - Through 1 Plugin

The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. The vendor decided to close the plugin.

PLUGIN Through 1

CVE-2021-24247

MEDIUM CVSS 5.4 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24223 - Through 1 Plugin

The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case of misconfigured servers with Directory listing enabled, accessing it is trivial.

PLUGIN Through 1

CVE-2021-24223

CRITICAL CVSS 9.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24224 - Through 1 Plugin

The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE.

PLUGIN Through 1

CVE-2021-24224

HIGH CVSS 8.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24174 - Through 1 Plugin

The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.

PLUGIN Through 1

CVE-2021-24174

HIGH CVSS 8.1 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24176 - Through 1 Plugin

The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.

PLUGIN Through 1

CVE-2021-24176

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24173 - Through 1 Plugin

The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.

PLUGIN Through 1

CVE-2021-24173

MEDIUM CVSS 6.1 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24172 - Through 1 Plugin

The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .

PLUGIN Through 1

CVE-2021-24172

MEDIUM CVSS 4.3 2021-04-05
Scroll to top