Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15561-15580 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24819 - Page Post Content Shortcode Plugin

The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.

PLUGIN Page Post Content Shortcode

CVE-2021-24819

MEDIUM CVSS 4.3 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24818 - Wp Limits Plugin

The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make a logged in admin change them, which could make the blog unstable by setting low values

PLUGIN Wp Limits

CVE-2021-24818

MEDIUM CVSS 4.3 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24790 - Contact Form Advanced Database Plugin

The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

PLUGIN Contact Form Advanced Database

CVE-2021-24790

MEDIUM CVSS 4.3 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24780 - Single Post Exporter Plugin

The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and give access to the export feature to any role such as subscriber. Subscriber users would then be able to export an arbitrary post/page (such as private and password protected) via a direct URL

PLUGIN Single Post Exporter

CVE-2021-24780

MEDIUM CVSS 4.3 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24943 - Registrations For The Events Calendar Plugin

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

PLUGIN Registrations For The Events Calendar

CVE-2021-24943

CRITICAL CVSS 9.8 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24931 - Secure Copy Content Protection And Content Locking Plugin

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

PLUGIN Secure Copy Content Protection And Content Locking

CVE-2021-24931

CRITICAL CVSS 9.8 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24866 - Wp Data Access Plugin

The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion

PLUGIN Wp Data Access

CVE-2021-24866

CRITICAL CVSS 9.8 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24914 - To Live Chat Plugin

The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-privileged users (including simple subscribers) to change the 'tawkto-embed-widget-page-id' and 'tawkto-embed-widget-widget-id' parameters. Any authenticated user can thus link the vulnerable website to their own Tawk.to instance. Consequently, they will be able to monitor the vulnerable website and interact with its visitors (receive contact messages, answer, ...). They will also be able to display an arbitrary Knowledge Base. The second…

PLUGIN To Live Chat

CVE-2021-24914

HIGH CVSS 8.0 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24917 - Wps Hide Login Plugin

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

PLUGIN Wps Hide Login

CVE-2021-24917

HIGH CVSS 7.5 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-25041 - Before 1 Plugin

The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action

PLUGIN Before 1

CVE-2021-25041

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24939 - Before 3 Plugin

The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and rul_logout_url parameter before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24939

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24938 - Before 1 Plugin

The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24938

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24935 - Wp Google Fonts Plugin

The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues

PLUGIN Wp Google Fonts

CVE-2021-24935

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24924 - Before 2 Plugin

The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-24924

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24759 - Before 2 Plugin

The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2021-24759

MEDIUM CVSS 5.4 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24718 - Popup Form Plugin For

The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Popup Form Plugin For

CVE-2021-24718

MEDIUM CVSS 4.8 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24714 - Import Any Xml Or Csv File To Plugin

The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier fields before outputting them in admin pages, which could allow high privilege users to perform Cross-Site attacks even when the unfiltered_html capability is disallowed.

PLUGIN Import Any Xml Or Csv File To

CVE-2021-24714

MEDIUM CVSS 4.8 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-42364 - Stetic Plugin

The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.0.6.

PLUGIN Stetic

CVE-2021-42364

HIGH CVSS 8.8 2021-11-29
Scroll to top