Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15621-15640 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24700 - Before 1 Plugin

The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 1

CVE-2021-24700

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24668 - Before 1 Plugin

The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack

PLUGIN Before 1

CVE-2021-24668

MEDIUM CVSS 4.3 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-43409 - Wordpress Azure Ad Microsoft Office 365 Plugin

The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected…

PLUGIN Wordpress Azure Ad Microsoft Office 365

CVE-2021-43409

CRITICAL CVSS 9.3 2021-11-19
Threat Entry Updated 2024-11-21

CVE-2021-39353 - Easy Registration Forms Plugin

The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 2.1.1.

PLUGIN Easy Registration Forms

CVE-2021-39353

HIGH CVSS 8.8 2021-11-19
Threat Entry Updated 2024-11-21

CVE-2021-43408 - Duplicate Post Plugin

The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default,…

PLUGIN Duplicate Post

CVE-2021-43408

MEDIUM CVSS 6.5 2021-11-19
Threat Entry Updated 2024-11-21

CVE-2021-42363 - Preview E Mails For Woocommerce Plugin

The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.6.8.

PLUGIN Preview E Mails For Woocommerce

CVE-2021-42363

MEDIUM CVSS 6.1 2021-11-19
Threat Entry Updated 2024-11-21

CVE-2021-42361 - Contact Form Email Plugin

The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.3.24. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Contact Form Email

CVE-2021-42361

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-42362 - Wordpress Popular Posts Plugin

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.

PLUGIN Wordpress Popular Posts

CVE-2021-42362

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-42360 - Starter Templates Plugin

On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to astra-page-elementor-batch-process and the url parameter pointed to their remotely-hosted malicious block, as well as an id parameter containing the…

PLUGIN Starter Templates

CVE-2021-42360

HIGH CVSS 7.6 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24847 - 301 Redirect Manager Plugin

The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed

PLUGIN 301 Redirect Manager

CVE-2021-24847

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24852 - Mousewheel Smooth Scroll Plugin

The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make a logged in admin change them via a CSRF attack

PLUGIN Mousewheel Smooth Scroll

CVE-2021-24852

MEDIUM CVSS 6.5 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24854 - Qr Redirector Plugin

The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks.

PLUGIN Qr Redirector

CVE-2021-24854

MEDIUM CVSS 5.4 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24850 - Insert Pages Plugin

The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by storing the payload/s in another post's custom fields.

PLUGIN Insert Pages

CVE-2021-24850

MEDIUM CVSS 5.4 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24834 - Before 6 Plugin

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of custom label parameters - vote button label , results link label and back to vote caption label.

PLUGIN Before 6

CVE-2021-24834

MEDIUM CVSS 5.4 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24833 - Yop Poll Plugin

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of question and answer text parameters in Create Poll module.

PLUGIN Yop Poll

CVE-2021-24833

MEDIUM CVSS 5.4 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24856 - Shared Files Plugin

The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Shared Files

CVE-2021-24856

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24841 - Before 4 Plugin

The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 4

CVE-2021-24841

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24815 - Accept Donations With Paypal Plugin

The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Accept Donations With Paypal

CVE-2021-24815

MEDIUM CVSS 4.8 2021-11-17
Scroll to top