Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15221-15240 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2022-0377 - Users Of The Learnpress Plugin

Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming and cropping of the image. As a result of this request, the name of the user-supplied image is changed with a MD5 value. This process can be conducted only when type of the image is JPG or PNG. An attacker can use…

PLUGIN Users Of The Learnpress

CVE-2022-0377

MEDIUM CVSS 4.3 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25010 - Post Snippets Plugin

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues

PLUGIN Post Snippets

CVE-2021-25010

CRITICAL CVSS 9.6 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25081 - Maps Plugin Using Google Maps For

The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack

PLUGIN Maps Plugin Using Google Maps For

CVE-2021-25081

MEDIUM CVSS 6.5 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0189 - Before 4 Plugin

The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting

PLUGIN Before 4

CVE-2022-0189

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0150 - Before 0 Plugin

The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 0

CVE-2022-0150

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25112 - Before 6 Plugin

The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 6

CVE-2021-25112

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25034 - Before 7 Plugin

The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 7

CVE-2021-25034

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24994 - Before 0 Plugin

The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue

PLUGIN Before 0

CVE-2021-24994

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2026-01-13

CVE-2021-24977 - Custom Font Uploader Plugin

The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to sent arbitrary CSS which will then be processed by the frontend for all users. Due to the lack of sanitisation and escaping in the backend, it could also lead to Stored XSS issues

PLUGIN Custom Font Uploader

CVE-2021-24977

MEDIUM CVSS 6.1 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25011 - Maps Plugin Using Google Maps For

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

PLUGIN Maps Plugin Using Google Maps For

CVE-2021-25011

MEDIUM CVSS 5.7 2022-02-28
Threat Entry Updated 2026-03-06

CVE-2021-25042 - Before 5 Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack of validation, sanitisation and escaping, users could set a malicious value and perform Cross-Site Scripting attacks against logged in admin

PLUGIN Before 5

CVE-2021-25042

MEDIUM CVSS 5.4 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24971 - Wp Responsive Menu Plugin

The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting attacks against all visitor and users on the frontend

PLUGIN Wp Responsive Menu

CVE-2021-24971

MEDIUM CVSS 5.4 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24933 - Dynamic Widgets Plugin

The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue

PLUGIN Dynamic Widgets

CVE-2021-24933

MEDIUM CVSS 5.4 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-25118 - Yoast Seo Plugin

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

PLUGIN Yoast Seo

CVE-2021-25118

MEDIUM CVSS 5.3 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24920 - Statcounter Plugin

The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Statcounter

CVE-2021-24920

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24903 - Grand Flagallery Plugin

The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Grand Flagallery

CVE-2021-24903

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24901 - Security Audit Plugin

The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Security Audit

CVE-2021-24901

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-4222 - Wp Paginate Plugin

The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Wp Paginate

CVE-2021-4222

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0328 - Before 4 Plugin

The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Before 4

CVE-2022-0328

MEDIUM CVSS 4.7 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0345 - Customize Wordpress Emails And Alerts Plugin

The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).

PLUGIN Customize Wordpress Emails And Alerts

CVE-2022-0345

MEDIUM CVSS 4.3 2022-02-28
Scroll to top