Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15321-15340 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2021-25095 - Ip2location Country Blocker Plugin

The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

PLUGIN Ip2location Country Blocker

CVE-2021-25095

HIGH CVSS 7.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25077 - Store Toolkit For Woocommerce Plugin

The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting

PLUGIN Store Toolkit For Woocommerce

CVE-2021-25077

MEDIUM CVSS 6.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25029 - E Learning Platform Plugin

The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN E Learning Platform

CVE-2021-25029

MEDIUM CVSS 4.8 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25084 - Advanced Cron Manager Plugin

The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

PLUGIN Advanced Cron Manager

CVE-2021-25084

MEDIUM CVSS 4.3 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24993 - Ultimate Product Catalog Plugin

The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example

PLUGIN Ultimate Product Catalog

CVE-2021-24993

MEDIUM CVSS 6.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24947 - Before 6 Plugin

The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server

PLUGIN Before 6

CVE-2021-24947

MEDIUM CVSS 6.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24928 - Rearrange Woocommerce Products Plugin

The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_order AJAX action, nor validation and escaping when inserting user data in SQL statement, leading to an SQL injection, and allowing any authenticated user, such as subscriber, to modify arbitrary post content (for example with an XSS payload), as well as exfiltrate any data by copying it to another post.

PLUGIN Rearrange Woocommerce Products

CVE-2021-24928

MEDIUM CVSS 6.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25004 - Seur Oficial Plugin

The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.

PLUGIN Seur Oficial

CVE-2021-25004

MEDIUM CVSS 4.9 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24879 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.

PLUGIN Before 2

CVE-2021-24879

HIGH CVSS 8.8 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24843 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action.

PLUGIN Before 2

CVE-2021-24843

MEDIUM CVSS 6.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24878 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-24878

MEDIUM CVSS 6.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24880 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2021-24880

MEDIUM CVSS 5.4 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24839 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions may be affected as well.

PLUGIN Before 2

CVE-2021-24839

HIGH CVSS 7.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2022-0218 - Wp Html Mail Plugin

The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.

PLUGIN Wp Html Mail

CVE-2022-0218

HIGH CVSS 8.3 2022-02-04
Threat Entry Updated 2024-11-21

CVE-2022-0381 - Embed Swagger Plugin

The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0.

PLUGIN Embed Swagger

CVE-2022-0381

MEDIUM CVSS 6.1 2022-02-04
Threat Entry Updated 2024-11-21

CVE-2022-0380 - Fotobook Plugin

The Fotobook WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping and the use of $_SERVER['PHP_SELF'] found in the ~/options-fotobook.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 3.2.3.

PLUGIN Fotobook

CVE-2022-0380

MEDIUM CVSS 6.1 2022-02-04
Threat Entry Updated 2024-11-21

CVE-2022-0320 - Essential Addons For Elementor Plugin

The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and read arbitrary files on the server, this could also lead to RCE via user uploaded files or other LFI to RCE techniques.

PLUGIN Essential Addons For Elementor

CVE-2022-0320

CRITICAL CVSS 9.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25093 - Link Library Plugin

The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request

PLUGIN Link Library

CVE-2021-25093

HIGH CVSS 7.5 2022-02-01
Scroll to top