Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15681-15700 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24626 - Chameleon Css Plugin

The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape the css_id POST parameter before using it in a SQL statement, leading to a SQL Injection

PLUGIN Chameleon Css

CVE-2021-24626

HIGH CVSS 8.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24575 - Before 2 Plugin

The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.

PLUGIN Before 2

CVE-2021-24575

HIGH CVSS 8.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24647 - Invitation Codes Plugin

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

PLUGIN Invitation Codes

CVE-2021-24647

HIGH CVSS 8.1 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24629 - Post Content Xmlrpc Plugin

The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before using them in SQL statements in the admin dashboard, leading to an authenticated SQL Injections

PLUGIN Post Content Xmlrpc

CVE-2021-24629

HIGH CVSS 7.2 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24628 - Wow Forms Plugin

The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection

PLUGIN Wow Forms

CVE-2021-24628

HIGH CVSS 7.2 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24627 - G Auto Hyperlink Plugin

The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection

PLUGIN G Auto Hyperlink

CVE-2021-24627

HIGH CVSS 7.2 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24625 - Spidercatalog Plugin

The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from the admin dashboard before using them in a SQL statement, leading to a SQL injection when adding a category

PLUGIN Spidercatalog

CVE-2021-24625

HIGH CVSS 7.2 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24537 - Similar Posts Plugin

The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened environment (ie with DISALLOW_FILE_EDIT, DISALLOW_FILE_MODS and DISALLOW_UNFILTERED_HTML set to true) via the 'widget_rrm_similar_posts_condition' widget setting of the plugin.

PLUGIN Similar Posts

CVE-2021-24537

HIGH CVSS 7.2 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24674 - Genie Wp Favicon Plugin

The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack

PLUGIN Genie Wp Favicon

CVE-2021-24674

MEDIUM CVSS 6.5 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24664 - Before 2 Plugin

The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.

PLUGIN Before 2

CVE-2021-24664

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24646 - Com Banner Creator Plugin

The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Com Banner Creator

CVE-2021-24646

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24645 - Com Product Helper Plugin

The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Com Product Helper

CVE-2021-24645

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24616 - Addtoany Share Buttons Plugin

The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Addtoany Share Buttons

CVE-2021-24616

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24607 - Storefront Footer Text Plugin

The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.

PLUGIN Storefront Footer Text

CVE-2021-24607

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24594 - Google Language Translator Plugin

The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Google Language Translator

CVE-2021-24594

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-39341 - Optinmonster Plugin

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.

PLUGIN Optinmonster

CVE-2021-39341

HIGH CVSS 8.2 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-39346 - Google Maps Easy Plugin

The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Google Maps Easy

CVE-2021-39346

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-39340 - Notification Plugin

The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 7.2.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Notification

CVE-2021-39340

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24809 - Before 1 Plugin

The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actions

PLUGIN Before 1

CVE-2021-24809

HIGH CVSS 8.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24770 - Stylish Price List Plugin

The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscriber, to upload arbitrary images.

PLUGIN Stylish Price List

CVE-2021-24770

MEDIUM CVSS 6.5 2021-11-01
Scroll to top