Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15301-15320 of 16358 records
Threat Entry Updated 2026-03-20

CVE-2021-25115 - Before 8 Plugin

The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.

PLUGIN Before 8

CVE-2021-25115

MEDIUM CVSS 6.4 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25107 - Form Store To Db Plugin

The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks against admin

PLUGIN Form Store To Db

CVE-2021-25107

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25033 - Wordpress Newsletter Plugin

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

PLUGIN Wordpress Newsletter

CVE-2021-25033

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25050 - Before 1 Plugin

The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Before 1

CVE-2021-25050

MEDIUM CVSS 4.8 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25109 - Futurio Extra Plugin

The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cross-Site Scripting (XSS) against logged in admins by making send open a malicious link.

PLUGIN Futurio Extra

CVE-2021-25109

LOW CVSS 2.7 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25018 - Ppom For Woocommerce Plugin

The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored XSS issues

PLUGIN Ppom For Woocommerce

CVE-2021-25018

MEDIUM CVSS 5.4 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-24446 - Remove Footer Credit Plugin

The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation

PLUGIN Remove Footer Credit

CVE-2021-24446

MEDIUM CVSS 5.4 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-24904 - Mortgage Calculators Wp Plugin

The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Mortgage Calculators Wp

CVE-2021-24904

MEDIUM CVSS 4.8 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25014 - Before 1 Plugin

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-25014

LOW CVSS 3.5 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0149 - Before 2 Plugin

The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.

PLUGIN Before 2

CVE-2022-0149

MEDIUM CVSS 6.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2022-0148 - Social Icon Tabs Plugin

The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.

PLUGIN Social Icon Tabs

CVE-2022-0148

MEDIUM CVSS 5.4 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25114 - Paid Memberships Pro Plugin

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

PLUGIN Paid Memberships Pro

CVE-2021-25114

CRITICAL CVSS 9.8 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25108 - Ip2location Country Blocker Plugin

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

PLUGIN Ip2location Country Blocker

CVE-2021-25108

HIGH CVSS 7.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25106 - Before 2 Plugin

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site Scripting

PLUGIN Before 2

CVE-2021-25106

MEDIUM CVSS 5.4 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25105 - Ivory Search Plugin

The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Ivory Search

CVE-2021-25105

MEDIUM CVSS 4.8 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25103 - Translate Wordpress With Gtranslate Plugin

The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY

PLUGIN Translate Wordpress With Gtranslate

CVE-2021-25103

MEDIUM CVSS 4.7 2022-02-07
Scroll to top