Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15161-15180 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2021-25003 - Before 6 Plugin

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

PLUGIN Before 6

CVE-2021-25003

CRITICAL CVSS 9.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24959 - Wp Email Users Plugin

The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks.

PLUGIN Wp Email Users

CVE-2021-24959

HIGH CVSS 8.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24692 - Simple Download Monitor Plugin

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

PLUGIN Simple Download Monitor

CVE-2021-24692

MEDIUM CVSS 6.5 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24982 - Child Theme Generator Plugin

The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting it back, leading to a Reflected Cross-Site Scripting in the admin dashboard

PLUGIN Child Theme Generator

CVE-2021-24982

MEDIUM CVSS 6.4 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24996 - Idpay For Contact Form 7 Plugin

The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter before outputting it back in the page leading to a Reflected Cross-Site Scripting

PLUGIN Idpay For Contact Form 7

CVE-2021-24996

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24940 - Persian Woocommerce Plugin

The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue

PLUGIN Persian Woocommerce

CVE-2021-24940

MEDIUM CVSS 6.1 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24958 - Meks Easy Photo Feed Widget Plugin

The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_business_selected_account AJAX action, available to any authenticated user, and does not escape some of the settings. As a result, any authenticated user, such as subscriber could update the plugin's settings and put Cross-Site Scripting payloads in them

PLUGIN Meks Easy Photo Feed Widget

CVE-2021-24958

MEDIUM CVSS 5.4 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24950 - Insight Core Plugin

The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before outputting it in the response. As a result, it could allow users with a role as low as Subscriber to perform PHP Object Injection, as well as Stored Cross-Site Scripting attacks

PLUGIN Insight Core

CVE-2021-24950

MEDIUM CVSS 5.4 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24897 - Add Subtitle Plugin

The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with classic editor) when output in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

PLUGIN Add Subtitle

CVE-2021-24897

MEDIUM CVSS 5.4 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24966 - Error Log Viewer Plugin

The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

PLUGIN Error Log Viewer

CVE-2021-24966

MEDIUM CVSS 4.9 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24995 - Html5 Responsive Faq Plugin

The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Html5 Responsive Faq

CVE-2021-24995

MEDIUM CVSS 4.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24895 - Before 1 Plugin

The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24895

MEDIUM CVSS 4.8 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0441 - Before 2 Plugin

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

PLUGIN Before 2

CVE-2022-0441

CRITICAL CVSS 9.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0434 - Page View Count Plugin

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

PLUGIN Page View Count

CVE-2022-0434

CRITICAL CVSS 9.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0349 - Before 2 Plugin

The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

PLUGIN Before 2

CVE-2022-0349

CRITICAL CVSS 9.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0439 - Before 5 Plugin

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

PLUGIN Before 5

CVE-2022-0439

HIGH CVSS 8.8 2022-03-07
Threat Entry Updated 2026-03-06

CVE-2022-0410 - Before 5 Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection

PLUGIN Before 5

CVE-2022-0410

HIGH CVSS 8.8 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0440 - Catch Themes Demo Import Plugin

The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true)

PLUGIN Catch Themes Demo Import

CVE-2022-0440

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0420 - Before 5 Plugin

The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks

PLUGIN Before 5

CVE-2022-0420

HIGH CVSS 7.2 2022-03-07
Scroll to top