Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15721-15740 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24570 - Accept Donations With Paypal Plugin

The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.

PLUGIN Accept Donations With Paypal

CVE-2021-24570

MEDIUM CVSS 4.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24884 - Formidable Form Builder Plugin

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attacker to perform arbitrary actions on an affected…

PLUGIN Formidable Form Builder

CVE-2021-24884

CRITICAL CVSS 9.6 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24487 - St Daily Tip Plugin

The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and was also lacking sanitisation as well as escaping before outputting it the page. This could allow attacker to make logged in administrators set a malicious payload in it, leading to a Stored Cross-Site Scripting issue

PLUGIN St Daily Tip

CVE-2021-24487

HIGH CVSS 8.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24774 - Before 1 Plugin

The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues

PLUGIN Before 1

CVE-2021-24774

HIGH CVSS 7.2 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24769 - Permalink Manager Lite Plugin

The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injection

PLUGIN Permalink Manager Lite

CVE-2021-24769

HIGH CVSS 7.2 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24662 - Game Server Status Plugin

The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it in SQL statement, leading to an Authenticated SQL Injection in an admin page

PLUGIN Game Server Status

CVE-2021-24662

HIGH CVSS 7.2 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24779 - Wp Debugging Plugin

The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by unauthenticated users.

PLUGIN Wp Debugging

CVE-2021-24779

MEDIUM CVSS 6.5 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24885 - Before 6 Plugin

The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Before 6

CVE-2021-24885

MEDIUM CVSS 6.1 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24543 - Jquery Reply To Comment Plugin

The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor sanitise or escape its 'Quote String' and 'Reply String' settings before outputting them in Comments, leading to a Stored Cross-Site Scripting issue.

PLUGIN Jquery Reply To Comment

CVE-2021-24543

MEDIUM CVSS 6.1 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24699 - Easy Media Download Plugin

The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Easy Media Download

CVE-2021-24699

MEDIUM CVSS 5.4 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24544 - Motopress Slider Lite Plugin

The Responsive WordPress Slider WordPress plugin through 2.2.0 does not sanitise and escape some of the Slider options, allowing Cross-Site Scripting payloads to be set in them. Furthermore, as by default any authenticated user is allowed to create Sliders (https://wordpress.org/support/topic/slider-can-be-changed-from-any-user-even-subscriber/, such settings can be changed in the plugin's settings), this would allow user with a role as low as subscriber to perform Cross-Site Scripting attacks against logged in admins viewing the slider list and could lead to privilege escalation by creating a rogue admin account for example.

PLUGIN Motopress Slider Lite

CVE-2021-24544

MEDIUM CVSS 5.4 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24785 - Great Quotes Plugin

The Great Quotes WordPress plugin through 1.0.0 does not sanitise and escape the Quote and Author fields of its Quotes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Great Quotes

CVE-2021-24785

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24744 - Wordpress Contact Forms By Cimatti Plugin

The WordPress Contact Forms by Cimatti WordPress plugin before 1.4.12 does not sanitise and escape the Form Title before outputting it in some admin pages. which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Wordpress Contact Forms By Cimatti

CVE-2021-24744

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24653 - Before 1 Plugin

The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24653

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24608 - Quiz Forms Plugin

The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Quiz Forms

CVE-2021-24608

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24515 - Video Gallery Plugin

The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues

PLUGIN Video Gallery

CVE-2021-24515

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24514 - Visual Form Builder Plugin

The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

PLUGIN Visual Form Builder

CVE-2021-24514

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24489 - Request A Quote Plugin

The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.

PLUGIN Request A Quote

CVE-2021-24489

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24485 - Special Text Boxes Plugin

The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Special Text Boxes

CVE-2021-24485

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24414 - Video Player For Youtube Plugin

The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

PLUGIN Video Player For Youtube

CVE-2021-24414

MEDIUM CVSS 5.4 2021-10-25
Scroll to top