Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15461-15480 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-25051 - Modal Window Plugin

The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Modal Window

CVE-2021-25051

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25032 - Before 2 Plugin

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.

PLUGIN Before 2

CVE-2021-25032

CRITICAL CVSS 9.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-24948 - Plus Addons For Elementor Pro Plugin

The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as private and draft posts

PLUGIN Plus Addons For Elementor Pro

CVE-2021-24948

HIGH CVSS 7.5 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-24862 - Before 5 Plugin

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

PLUGIN Before 5

CVE-2021-24862

HIGH CVSS 7.2 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25047 - 10web Social Photo Feed Plugin

The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users

PLUGIN 10web Social Photo Feed

CVE-2021-25047

MEDIUM CVSS 6.1 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25043 - Before 1 Plugin

The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-25043

MEDIUM CVSS 6.1 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25030 - Events Made Easy Plugin

The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it and perform SQL injection attacks

PLUGIN Events Made Easy

CVE-2021-25030

HIGH CVSS 8.8 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25023 - Pagespeed Optimization Suite Plugin

The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_table_name parameter before using it in a SQL statement to convert the related table, leading to an SQL injection

PLUGIN Pagespeed Optimization Suite

CVE-2021-25023

HIGH CVSS 7.2 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25040 - Booking Calendar Plugin

The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Booking Calendar

CVE-2021-25040

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25027 - Powerpack Addons For Elementor Plugin

The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Powerpack Addons For Elementor

CVE-2021-25027

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2025-05-22

CVE-2021-25022 - Before 1 Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 1

CVE-2021-25022

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25021 - Host Google Fonts Locally Plugin

The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin

PLUGIN Host Google Fonts Locally

CVE-2021-25021

MEDIUM CVSS 4.9 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24893 - Stars Rating Plugin

The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.

PLUGIN Stars Rating

CVE-2021-24893

HIGH CVSS 7.5 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24831 - All Ajax Actions Of The Tab Plugin

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.

PLUGIN All Ajax Actions Of The Tab

CVE-2021-24831

HIGH CVSS 7.5 2022-01-03
Threat Entry Updated 2025-05-22

CVE-2021-24786 - Download Monitor Plugin

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

PLUGIN Download Monitor

CVE-2021-24786

HIGH CVSS 7.2 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25016 - 3 And Chaty Pro Plugin

The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN 3 And Chaty Pro

CVE-2021-25016

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25001 - Booster For Woocommerce Plugin

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_create_products_xml_result parameter before outputting back in the admin dashboard when the Product XML Feeds module is enabled, leading to a Reflected Cross-Site Scripting issue

PLUGIN Booster For Woocommerce

CVE-2021-25001

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-25000 - Booster For Woocommerce Plugin

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter before outputting back in the admin dashboard when the General module is enabled, leading to a Reflected Cross-Site Scripting issue

PLUGIN Booster For Woocommerce

CVE-2021-25000

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24999 - Booster For Woocommerce Plugin

The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_notice parameter before outputting it back in the admin dashboard when the Pdf Invoicing module is enabled, leading to a Reflected Cross-Site Scripting

PLUGIN Booster For Woocommerce

CVE-2021-24999

MEDIUM CVSS 6.1 2022-01-03
Scroll to top