Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15541-15560 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24954 - Before 3 Plugin

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24954

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24932 - Before 3 Plugin

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.

PLUGIN Before 3

CVE-2021-24932

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24925 - Modern Events Calendar Lite Plugin

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN Modern Events Calendar Lite

CVE-2021-24925

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24871 - Get Custom Field Values Plugin

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

PLUGIN Get Custom Field Values

CVE-2021-24871

MEDIUM CVSS 5.4 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24855 - Display Post Metadata Plugin

The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

PLUGIN Display Post Metadata

CVE-2021-24855

MEDIUM CVSS 5.4 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24972 - Pixel Cat Plugin

The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Pixel Cat

CVE-2021-24972

MEDIUM CVSS 4.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24896 - Caldera Forms Plugin

The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Caldera Forms

CVE-2021-24896

MEDIUM CVSS 4.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-42546 - Use Your Drive Plugin

Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.

PLUGIN Use Your Drive

CVE-2021-42546

MEDIUM CVSS 4.7 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24859 - User Meta Shortcodes Plugin

The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes

PLUGIN User Meta Shortcodes

CVE-2021-24859

MEDIUM CVSS 4.3 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24747 - Before 3 Plugin

The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_ajax" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly escaped leading to blind and error-based SQL injections.

PLUGIN Before 3

CVE-2021-24747

HIGH CVSS 7.2 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24845 - Improved Include Page Plugin

The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor can gain access to content they are not supposed to.

PLUGIN Improved Include Page

CVE-2021-24845

MEDIUM CVSS 6.5 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24795 - Filter Portfolio Gallery Plugin

The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery.

PLUGIN Filter Portfolio Gallery

CVE-2021-24795

MEDIUM CVSS 6.5 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24784 - Wp Admin Logo Changer Plugin

The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.

PLUGIN Wp Admin Logo Changer

CVE-2021-24784

MEDIUM CVSS 6.5 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24792 - Shiny Buttons Plugin

The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outputting them in the admin dashboard, which allow unauthenticated users to add a malicious template and lead to Stored Cross-Site Scripting issues.

PLUGIN Shiny Buttons

CVE-2021-24792

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24756 - Wp System Log Plugin

The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.

PLUGIN Wp System Log

CVE-2021-24756

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24817 - Ultimate Nofollow Plugin

The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks

PLUGIN Ultimate Nofollow

CVE-2021-24817

MEDIUM CVSS 5.4 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24782 - Flex Local Fonts Plugin

The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Flex Local Fonts

CVE-2021-24782

MEDIUM CVSS 4.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24771 - Inspirational Quote Rotator Plugin

The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the "Quotes list" even when the unfiltered_html capability is disallowed

PLUGIN Inspirational Quote Rotator

CVE-2021-24771

MEDIUM CVSS 4.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24705 - Before 8 Plugin

The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape some of its settings as well as form fields before outputting them in attributes. This could allow attackers to make a logged in admin edit arbitrary forms with Cross-Site Scripting payloads in them

PLUGIN Before 8

CVE-2021-24705

MEDIUM CVSS 4.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24836 - Temporary Login Without Password Plugin

The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them

PLUGIN Temporary Login Without Password

CVE-2021-24836

MEDIUM CVSS 4.3 2021-12-13
Scroll to top