Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15601-15620 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-20846 - Push Notifications For Wp Plugin

Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.

PLUGIN Push Notifications For Wp

CVE-2021-20846

HIGH CVSS 8.8 2021-11-24
Threat Entry Updated 2024-11-21

CVE-2021-24892 - Advanced Forms Plugin

Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To exploit this vulnerability, an attacker must register to obtain a valid WordPress's user and use such user to authenticate with WordPress in order to exploit the vulnerable edit function.

PLUGIN Advanced Forms

CVE-2021-24892

HIGH CVSS 8.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24877 - Mainwp Child Plugin

The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed

PLUGIN Mainwp Child

CVE-2021-24877

HIGH CVSS 7.2 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24894 - Reviews Plus Plugin

The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page

PLUGIN Reviews Plus

CVE-2021-24894

MEDIUM CVSS 6.5 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24875 - Ecommerce Product Catalog Plugin

The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Ecommerce Product Catalog

CVE-2021-24875

MEDIUM CVSS 6.1 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24873 - Before 1 Plugin

The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24873

MEDIUM CVSS 6.1 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24888 - Before 3 Plugin

The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high privilege users to perform Cross-Site Scripting attacks

PLUGIN Before 3

CVE-2021-24888

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24882 - Slideshow Gallery Plugin

The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Slideshow Gallery

CVE-2021-24882

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24830 - Advanced Access Manager Plugin

The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Advanced Access Manager

CVE-2021-24830

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24641 - Images To Webp Plugin

The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion

PLUGIN Images To Webp

CVE-2021-24641

HIGH CVSS 8.1 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24644 - Images To Webp Plugin

The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

PLUGIN Images To Webp

CVE-2021-24644

HIGH CVSS 7.5 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24703 - Before 1 Plugin

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

PLUGIN Before 1

CVE-2021-24703

MEDIUM CVSS 5.7 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24812 - Before 1 Plugin

The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.

PLUGIN Before 1

CVE-2021-24812

MEDIUM CVSS 5.4 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24729 - Logo Showcase With Slick Slider Plugin

The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.

PLUGIN Logo Showcase With Slick Slider

CVE-2021-24729

MEDIUM CVSS 5.4 2021-11-23
Threat Entry Updated 2026-01-23

CVE-2021-24713 - Video Lessons Manager Plugin

The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks

PLUGIN Video Lessons Manager

CVE-2021-24713

MEDIUM CVSS 4.8 2021-11-23
Scroll to top