Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15401-15420 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2021-24694 - Simple Download Monitor Plugin

The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.

PLUGIN Simple Download Monitor

CVE-2021-24694

MEDIUM CVSS 5.4 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24423 - Updraftplus Wordpress Backup Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

PLUGIN Updraftplus Wordpress Backup

CVE-2021-24423

MEDIUM CVSS 4.8 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24733 - Wp Post Page Clone Plugin

The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.

PLUGIN Wp Post Page Clone

CVE-2021-24733

MEDIUM CVSS 4.3 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-44777 - Email Tracker Plugin

Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email Tracker WordPress plugin (versions

PLUGIN Email Tracker

CVE-2021-44777

MEDIUM CVSS 5.4 2022-01-19
Threat Entry Updated 2024-11-21

CVE-2022-0215 - Side Cart Woocommerce Plugin

The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site. This affects versions

PLUGIN Side Cart Woocommerce

CVE-2022-0215

HIGH CVSS 8.8 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2022-0236 - Wp Import Export Plugin

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.

PLUGIN Wp Import Export

CVE-2022-0236

HIGH CVSS 7.5 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2022-0233 - Profilegrid User Profiles Groups And Communities Plugin

The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7.

PLUGIN Profilegrid User Profiles Groups And Communities

CVE-2022-0233

MEDIUM CVSS 6.4 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2022-0232 - Custom Landing Pages Leadmagic Plugin

The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.2.7. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Custom Landing Pages Leadmagic

CVE-2022-0232

MEDIUM CVSS 4.8 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2022-0210 - Random Banner Plugin

The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Random Banner

CVE-2022-0210

MEDIUM CVSS 4.8 2022-01-18
Threat Entry Updated 2025-02-14

CVE-2021-43353 - Crisp Plugin

The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 0.31.

PLUGIN Crisp

CVE-2021-43353

HIGH CVSS 8.8 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2021-4074 - Whmcs Bridge Plugin

The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge_add_admin function, low-level authenticated users such as subscribers can exploit this vulnerability.

PLUGIN Whmcs Bridge

CVE-2021-4074

MEDIUM CVSS 6.4 2022-01-18
Threat Entry Updated 2024-11-21

CVE-2021-25061 - Before 2 Plugin

The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.

PLUGIN Before 2

CVE-2021-25061

MEDIUM CVSS 5.4 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25036 - All In One Seo Plugin

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.

PLUGIN All In One Seo

CVE-2021-25036

HIGH CVSS 8.8 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25037 - All In One Seo Plugin

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).

PLUGIN All In One Seo

CVE-2021-25037

MEDIUM CVSS 6.5 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25024 - Before 1 Plugin

The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues

PLUGIN Before 1

CVE-2021-25024

MEDIUM CVSS 6.1 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-24909 - Acf Photo Gallery Field Plugin

The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Acf Photo Gallery Field

CVE-2021-24909

MEDIUM CVSS 6.1 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-24838 - Before 0 Plugin

The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

PLUGIN Before 0

CVE-2021-24838

MEDIUM CVSS 6.1 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25046 - Modern Events Calendar Lite Plugin

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.

PLUGIN Modern Events Calendar Lite

CVE-2021-25046

MEDIUM CVSS 5.4 2022-01-17
Scroll to top