Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15701-15720 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24742 - Logo Slider And Showcase Plugin

The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.

PLUGIN Logo Slider And Showcase

CVE-2021-24742

MEDIUM CVSS 6.5 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24808 - Bp Better Messages Plugin

The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Bp Better Messages

CVE-2021-24808

MEDIUM CVSS 6.1 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24723 - Wp Reactions Lite Plugin

The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.

PLUGIN Wp Reactions Lite

CVE-2021-24723

MEDIUM CVSS 5.4 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24757 - Stylish Price List Plugin

The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated users to upload images.

PLUGIN Stylish Price List

CVE-2021-24757

MEDIUM CVSS 5.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24813 - Before 2 Plugin

The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2021-24813

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24794 - Connections Business Directory Plugin

The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.

PLUGIN Connections Business Directory

CVE-2021-24794

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24793 - Wpematico Rss Feed Fetcher Plugin

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Wpematico Rss Feed Fetcher

CVE-2021-24793

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24789 - Flat Preloader Plugin

The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Flat Preloader

CVE-2021-24789

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2025-03-21

CVE-2021-24773 - Wordpress Download Manager Plugin

The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed

PLUGIN Wordpress Download Manager

CVE-2021-24773

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24799 - Far Future Expiry Header Plugin

The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Far Future Expiry Header

CVE-2021-24799

MEDIUM CVSS 4.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24781 - Before 2 Plugin

The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit)

PLUGIN Before 2

CVE-2021-24781

MEDIUM CVSS 4.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24717 - Before 1 Plugin

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

PLUGIN Before 1

CVE-2021-24717

HIGH CVSS 8.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24685 - Flat Preloader Plugin

The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)

PLUGIN Flat Preloader

CVE-2021-24685

MEDIUM CVSS 5.4 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24682 - Cool Tag Cloud Plugin

The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Cool Tag Cloud

CVE-2021-24682

MEDIUM CVSS 5.4 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24722 - Restaurant Menu By Motopress Plugin

The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Restaurant Menu By Motopress

CVE-2021-24722

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24715 - Wp Sitemap Page Plugin

The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Wp Sitemap Page

CVE-2021-24715

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24624 - Podcast By Sonaar Plugin

The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks

PLUGIN Podcast By Sonaar

CVE-2021-24624

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24539 - Maintenance Mode By Dazzler Plugin

The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Maintenance Mode By Dazzler

CVE-2021-24539

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24572 - Accept Donations With Paypal Plugin

The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts

PLUGIN Accept Donations With Paypal

CVE-2021-24572

MEDIUM CVSS 4.3 2021-11-01
Scroll to top