Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High1
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2024-12-26

CVE-2024-8481 - Wp Special Textboxes Plugin

The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.2. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN Wp Special Textboxes

CVE-2024-8481

HIGH CVSS 7.3 2024-09-25
Threat Entry Updated 2024-11-21

CVE-2021-24485 - Wp Special Textboxes Plugin

The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Wp Special Textboxes

CVE-2021-24485

MEDIUM CVSS 4.8 2021-10-25
Scroll to top