Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15641-15660 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24853 - Qr Redirector Plugin

The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects

PLUGIN Qr Redirector

CVE-2021-24853

MEDIUM CVSS 4.3 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24851 - Insert Pages Plugin

The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.

PLUGIN Insert Pages

CVE-2021-24851

MEDIUM CVSS 4.3 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24804 - Simple Jwt Login Plugin

The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user roles can be updated, which could result in site takeover.

PLUGIN Simple Jwt Login

CVE-2021-24804

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24772 - Before 3 Plugin

The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.

PLUGIN Before 3

CVE-2021-24772

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24758 - Email Log Plugin

The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections

PLUGIN Email Log

CVE-2021-24758

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24802 - Colorful Categories Plugin

The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack

PLUGIN Colorful Categories

CVE-2021-24802

MEDIUM CVSS 6.5 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24796 - Before 1 Plugin

The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins

PLUGIN Before 1

CVE-2021-24796

MEDIUM CVSS 6.1 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24787 - Client Invoicing By Sprout Invoices Plugin

The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Client Invoicing By Sprout Invoices

CVE-2021-24787

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24598 - Before 1 Plugin

The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24598

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-41951 - N A Plugin

ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an attacker is able to persuade a victim to visit a crafted URL, malicious JavaScript content may be executed within the context of the victim's browser.

PLUGIN N A

CVE-2021-41951

MEDIUM CVSS 6.1 2021-11-15
Threat Entry Updated 2024-11-21

CVE-2021-24827 - Asgaros Forum Plugin

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

PLUGIN Asgaros Forum

CVE-2021-24827

CRITICAL CVSS 9.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24835 - Tend Manager For Woocommerce Along With Bookings Subscription Listings Compatible Plugin

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacks

PLUGIN Tend Manager For Woocommerce Along With Bookings Subscription Listings Compatible

CVE-2021-24835

HIGH CVSS 8.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24829 - Visitor Traffic Real Time Statistics Plugin

The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue

PLUGIN Visitor Traffic Real Time Statistics

CVE-2021-24829

HIGH CVSS 8.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24844 - Affiliates Manager Plugin

The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue

PLUGIN Affiliates Manager

CVE-2021-24844

HIGH CVSS 7.2 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24807 - Support Board Plugin

The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.

PLUGIN Support Board

CVE-2021-24807

MEDIUM CVSS 5.4 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24840 - Squaretype Plugin

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

PLUGIN Squaretype

CVE-2021-24840

MEDIUM CVSS 5.3 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24832 - Wp Seo Redirect 301 Plugin

The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Wp Seo Redirect 301

CVE-2021-24832

MEDIUM CVSS 4.3 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24816 - Phoenix Media Rename Plugin

The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.

PLUGIN Phoenix Media Rename

CVE-2021-24816

MEDIUM CVSS 4.3 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24806 - Before 7 Plugin

The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.

PLUGIN Before 7

CVE-2021-24806

MEDIUM CVSS 4.3 2021-11-08
Scroll to top