Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15741-15760 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24381 - Ninja Forms Contact Form Plugin

The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Ninja Forms Contact Form

CVE-2021-24381

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-39352 - Catch Themes Demo Import Plugin

The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution.

PLUGIN Catch Themes Demo Import

CVE-2021-39352

HIGH CVSS 7.2 2021-10-21
Threat Entry Updated 2024-11-21

CVE-2021-39357 - Leaky Paywall Plugin

The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the ~/class.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.16.5. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Leaky Paywall

CVE-2021-39357

MEDIUM CVSS 5.5 2021-10-21
Threat Entry Updated 2024-11-21

CVE-2021-39356 - Content Staging Plugin

The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via several parameters that are echo'd out via the ~/templates/settings.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.0.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Content Staging

CVE-2021-39356

MEDIUM CVSS 5.5 2021-10-21
Threat Entry Updated 2025-02-07

CVE-2021-39354 - Easy Digital Downloads Plugin

The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.

PLUGIN Easy Digital Downloads

CVE-2021-39354

MEDIUM CVSS 4.8 2021-10-21
Threat Entry Updated 2024-11-21

CVE-2021-39321 - Sassy Social Share Plugin

Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file. This can be exploited by underprivileged authenticated users due to a missing capability check on the import_config function.

PLUGIN Sassy Social Share

CVE-2021-39321

HIGH CVSS 8.8 2021-10-21
Threat Entry Updated 2024-11-21

CVE-2021-39348 - Learnpress Plugin

The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.3.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. Please note that this is seperate from CVE-2021-24702.

PLUGIN Learnpress

CVE-2021-39348

MEDIUM CVSS 5.5 2021-10-21
Threat Entry Updated 2024-11-21

CVE-2021-39328 - Simple Job Board Plugin

The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-settings-privacy.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 2.9.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Simple Job Board

CVE-2021-39328

MEDIUM CVSS 5.5 2021-10-21
Threat Entry Updated 2024-11-21

CVE-2021-39355 - Indeed Job Importer Plugin

The Indeed Job Importer WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/indeed-job-importer/trunk/indeed-job-importer.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.5. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Indeed Job Importer

CVE-2021-39355

MEDIUM CVSS 5.5 2021-10-19
Threat Entry Updated 2025-04-25

CVE-2021-39343 - Mpl Publisher Plugin

The MPL-Publisher WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/libs/PublisherController.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.30.2. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Mpl Publisher

CVE-2021-39343

MEDIUM CVSS 5.5 2021-10-19
Threat Entry Updated 2024-11-21

CVE-2021-39329 - Jobboardwp Plugin

The JobBoardWP WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-metabox.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.0.7. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.

PLUGIN Jobboardwp

CVE-2021-39329

MEDIUM CVSS 5.5 2021-10-19
Threat Entry Updated 2024-11-21

CVE-2021-24754 - Mainwp Child Reports Plugin

The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue

PLUGIN Mainwp Child Reports

CVE-2021-24754

HIGH CVSS 7.2 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24752 - Header Enhancement Plugin

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu WordPress plugin before…

PLUGIN Header Enhancement

CVE-2021-24752

MEDIUM CVSS 5.7 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24760 - Gutenberg Pdf Viewer Block Plugin

The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

PLUGIN Gutenberg Pdf Viewer Block

CVE-2021-24760

MEDIUM CVSS 5.4 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24684 - Wordpress Pdf Light Viewer Plugin

The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary OS command on the server via OS Command Injection when invoking Ghostscript.

PLUGIN Wordpress Pdf Light Viewer

CVE-2021-24684

HIGH CVSS 8.8 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24735 - Compact Wp Audio Player Plugin

The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.

PLUGIN Compact Wp Audio Player

CVE-2021-24735

MEDIUM CVSS 6.5 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24675 - One User Avatar Plugin

The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in user change their avatar via a CSRF attack

PLUGIN One User Avatar

CVE-2021-24675

MEDIUM CVSS 6.5 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24642 - Scroll Banner Plugin

The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS

PLUGIN Scroll Banner

CVE-2021-24642

MEDIUM CVSS 6.5 2021-10-18
Scroll to top