Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15341-15360 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2021-25097 - Labtools Plugin

The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication

PLUGIN Labtools

CVE-2021-25097

MEDIUM CVSS 6.5 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25092 - Link Library Plugin

The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack

PLUGIN Link Library

CVE-2021-25092

MEDIUM CVSS 6.5 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25072 - Social Networks Auto Poster Plugin

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack

PLUGIN Social Networks Auto Poster

CVE-2021-25072

MEDIUM CVSS 6.5 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2022-0220 - Settings Ajax Action Of The Wordpress Gdpr Plugin

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. Due to v1.9.26 adding a CSRF check, the XSS is only exploitable against unauthenticated users (as they all share the same nonce)

PLUGIN Settings Ajax Action Of The Wordpress Gdpr

CVE-2022-0220

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25091 - Link Library Plugin

The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Link Library

CVE-2021-25091

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25089 - Updraftplus Wordpress Backup Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting

PLUGIN Updraftplus Wordpress Backup

CVE-2021-25089

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25085 - Woof Plugin

The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Woof

CVE-2021-25085

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25063 - Skins For Contact Form 7 Plugin

The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Skins For Contact Form 7

CVE-2021-25063

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24983 - Page Speed Booster Plugin

The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue

PLUGIN Page Speed Booster

CVE-2021-24983

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24975 - Before 4 Plugin

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue

PLUGIN Before 4

CVE-2021-24975

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24944 - Before 7 Plugin

The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 7

CVE-2021-24944

MEDIUM CVSS 4.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24762 - Perfect Survey Plugin

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

PLUGIN Perfect Survey

CVE-2021-24762

CRITICAL CVSS 9.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24814 - Settings Ajax Action Of The Wordpress Gdpr Plugin

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. If the victim is an administrator with a valid session cookie, full control of the WordPress instance may be taken (AJAX calls and iframe manipulation are possible because the vulnerable endpoint is on the same…

PLUGIN Settings Ajax Action Of The Wordpress Gdpr

CVE-2021-24814

CRITICAL CVSS 9.6 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24919 - Before 2 Plugin

The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection

PLUGIN Before 2

CVE-2021-24919

HIGH CVSS 8.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24763 - Perfect Survey Plugin

The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could also lead to a Stored Cross-Site Scripting issue which will be executed in the context of a user viewing any survey

PLUGIN Perfect Survey

CVE-2021-24763

HIGH CVSS 8.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24761 - Error Log Viewer Plugin

The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.

PLUGIN Error Log Viewer

CVE-2021-24761

MEDIUM CVSS 6.5 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24937 - Page Speed Booster Plugin

The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Page Speed Booster

CVE-2021-24937

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24934 - Visual Css Style Editor Plugin

The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Visual Css Style Editor

CVE-2021-24934

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24926 - Domain Check Plugin

The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Domain Check

CVE-2021-24926

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24765 - Perfect Survey Plugin

The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading to a Stored Cross-Site Scripting issue

PLUGIN Perfect Survey

CVE-2021-24765

MEDIUM CVSS 6.1 2022-02-01
Scroll to top