Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15501-15520 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24849 - Controller Ajax Action Of The Wcfm Marketplace Plugin

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

PLUGIN Controller Ajax Action Of The Wcfm Marketplace

CVE-2021-24849

CRITICAL CVSS 9.8 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24846 - Function Of The Ni Woocommerce Custom Order Status Plugin

The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber

PLUGIN Function Of The Ni Woocommerce Custom Order Status

CVE-2021-24846

HIGH CVSS 8.8 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24981 - Before 7 Plugin

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

PLUGIN Before 7

CVE-2021-24981

HIGH CVSS 7.5 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24956 - Before 6 Plugin

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 6

CVE-2021-24956

MEDIUM CVSS 6.1 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24941 - Optins And Lead Generation Plugin

The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue

PLUGIN Optins And Lead Generation

CVE-2021-24941

MEDIUM CVSS 6.1 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24907 - Drag And Drop Form Builder For Plugin

The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Drag And Drop Form Builder For

CVE-2021-24907

MEDIUM CVSS 6.1 2021-12-21
Threat Entry Updated 2026-03-06

CVE-2021-24750 - Before 4 Plugin

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

PLUGIN Before 4

CVE-2021-24750

HIGH CVSS 8.8 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24739 - Logo Carousel Plugin

The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature

PLUGIN Logo Carousel

CVE-2021-24739

HIGH CVSS 8.1 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24578 - Before 2 Plugin

The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-24578

MEDIUM CVSS 6.1 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24738 - Logo Carousel Plugin

The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Logo Carousel

CVE-2021-24738

MEDIUM CVSS 5.4 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-4073 - Registrationmagic Plugin

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

PLUGIN Registrationmagic

CVE-2021-4073

CRITICAL CVSS 9.8 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-42367 - Variation Swatches For Woocommerce Plugin

The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/class-menu-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1. Due to missing authorization checks on the tawcvs_save_settings function, low-level authenticated users such as subscribers can exploit this vulnerability.

PLUGIN Variation Swatches For Woocommerce

CVE-2021-42367

MEDIUM CVSS 6.4 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-41836 - Fathom Analytics Plugin

The Fathom Analytics WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the $site_id parameter found in the ~/fathom-analytics.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 3.0.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Fathom Analytics

CVE-2021-41836

MEDIUM CVSS 4.8 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-39318 - H5p Css Editor Plugin

The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

PLUGIN H5p Css Editor

CVE-2021-39318

MEDIUM CVSS 6.1 2021-12-14
Threat Entry Updated 2024-11-21

CVE-2021-39315 - Magic Post Voice Plugin

The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the ~/inc/admin/main.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.

PLUGIN Magic Post Voice

CVE-2021-39315

MEDIUM CVSS 6.1 2021-12-14
Scroll to top