Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-03-21

CVE-2021-24969 - Wordpress Download Manager Plugin

The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks

PLUGIN Wordpress Download Manager

CVE-2021-24969

MEDIUM CVSS 5.4 2021-12-27
Threat Entry Updated 2025-03-21

CVE-2021-24773 - Wordpress Download Manager Plugin

The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed

PLUGIN Wordpress Download Manager

CVE-2021-24773

MEDIUM CVSS 4.8 2021-11-01
Scroll to top