Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total43
Critical0
High8
Medium33
Reset
Showing 41-43 of 43 records
Threat Entry Updated 2024-11-21

CVE-2021-24681 - Through 4 Plugin

The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Through 4

CVE-2021-24681

MEDIUM CVSS 4.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24490 - Through 4 Plugin

The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a CSRF attack as well. However, due to the presence of a .htaccess, denying access to everything in the folder the file is uploaded to, the malicious uploaded file will only be accessible on Web Servers such as Nginx/IIS

PLUGIN Through 4

CVE-2021-24490

MEDIUM CVSS 6.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24466 - Through 4 Plugin

The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues

PLUGIN Through 4

CVE-2021-24466

MEDIUM CVSS 6.1 2021-08-16
Scroll to top