Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15281-15300 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2021-24921 - Advanced Database Cleaner Plugin

The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Advanced Database Cleaner

CVE-2021-24921

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25060 - Five Star Business Profile And Schema Plugin

The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues

PLUGIN Five Star Business Profile And Schema

CVE-2021-25060

MEDIUM CVSS 5.4 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25058 - Buffer Button Plugin

The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within the Twitter username to mention text field.

PLUGIN Buffer Button

CVE-2021-25058

MEDIUM CVSS 5.4 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25101 - Anti Malware Security And Brute Force Firewall Plugin

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST data before outputting it back in attributes of an admin page, leading to a Reflected Cross-Site scripting. Due to the presence of specific parameter value, available to admin users, this can only be exploited by an admin against another admin user.

PLUGIN Anti Malware Security And Brute Force Firewall

CVE-2021-25101

MEDIUM CVSS 4.8 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25075 - Duplicate Page Or Post Plugin

The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues

PLUGIN Duplicate Page Or Post

CVE-2021-25075

LOW CVSS 3.5 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0633 - Free Plugin

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

PLUGIN Free

CVE-2022-0633

MEDIUM CVSS 6.5 2022-02-17
Threat Entry Updated 2024-11-21

CVE-2022-0513 - Wp Statistics Plugin

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.

PLUGIN Wp Statistics

CVE-2022-0513

CRITICAL CVSS 9.8 2022-02-16
Threat Entry Updated 2024-11-21

CVE-2021-4134 - Fancy Product Designer Plugin

The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 4.7.4.

PLUGIN Fancy Product Designer

CVE-2021-4134

HIGH CVSS 7.2 2022-02-16
Threat Entry Updated 2024-11-21

CVE-2022-0190 - Before 1 Plugin

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.

PLUGIN Before 1

CVE-2022-0190

HIGH CVSS 8.8 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0214 - Custom Popup Builder Plugin

The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog

PLUGIN Custom Popup Builder

CVE-2022-0214

HIGH CVSS 7.5 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0212 - Spidercalendar Plugin

The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.

PLUGIN Spidercalendar

CVE-2022-0212

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0208 - Mappress Maps For Plugin

The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting

PLUGIN Mappress Maps For

CVE-2022-0208

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0206 - Before 1 Plugin

The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 1

CVE-2022-0206

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0201 - Permalink Manager Lite Plugin

The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Permalink Manager Lite

CVE-2022-0201

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0193 - Before 6 Plugin

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 6

CVE-2022-0193

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0200 - Themify Portfolio Post Plugin

Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting

PLUGIN Themify Portfolio Post

CVE-2022-0200

MEDIUM CVSS 5.4 2022-02-14
Scroll to top