Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,358
Critical1,021
High3,397
Medium11,667
Reset
Showing 15421-15440 of 16358 records
Threat Entry Updated 2024-11-21

CVE-2021-25005 - Seur Oficial Plugin

The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Seur Oficial

CVE-2021-25005

MEDIUM CVSS 4.8 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25025 - Before 1 Plugin

The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

PLUGIN Before 1

CVE-2021-25025

MEDIUM CVSS 4.3 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25054 - Wpcalc Plugin

The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.

PLUGIN Wpcalc

CVE-2021-25054

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25053 - Before 2 Plugin

The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Before 2

CVE-2021-25053

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25052 - Before 2 Plugin

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Before 2

CVE-2021-25052

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25051 - Modal Window Plugin

The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Modal Window

CVE-2021-25051

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25032 - Before 2 Plugin

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.

PLUGIN Before 2

CVE-2021-25032

CRITICAL CVSS 9.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-24948 - Plus Addons For Elementor Pro Plugin

The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as private and draft posts

PLUGIN Plus Addons For Elementor Pro

CVE-2021-24948

HIGH CVSS 7.5 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-24862 - Before 5 Plugin

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

PLUGIN Before 5

CVE-2021-24862

HIGH CVSS 7.2 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25047 - 10web Social Photo Feed Plugin

The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users

PLUGIN 10web Social Photo Feed

CVE-2021-25047

MEDIUM CVSS 6.1 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25043 - Before 1 Plugin

The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-25043

MEDIUM CVSS 6.1 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25030 - Events Made Easy Plugin

The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it and perform SQL injection attacks

PLUGIN Events Made Easy

CVE-2021-25030

HIGH CVSS 8.8 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25023 - Pagespeed Optimization Suite Plugin

The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_table_name parameter before using it in a SQL statement to convert the related table, leading to an SQL injection

PLUGIN Pagespeed Optimization Suite

CVE-2021-25023

HIGH CVSS 7.2 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25040 - Booking Calendar Plugin

The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Booking Calendar

CVE-2021-25040

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25027 - Before 2 Plugin

The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-25027

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2025-05-22

CVE-2021-25022 - Updraftplus Wordpress Backup Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues

PLUGIN Updraftplus Wordpress Backup

CVE-2021-25022

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25021 - Host Google Fonts Locally Plugin

The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin

PLUGIN Host Google Fonts Locally

CVE-2021-25021

MEDIUM CVSS 4.9 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24893 - Stars Rating Plugin

The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.

PLUGIN Stars Rating

CVE-2021-24893

HIGH CVSS 7.5 2022-01-03
Scroll to top