Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15801-15820 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-24563 - Frontend Uploader Plugin

The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly

PLUGIN Frontend Uploader

CVE-2021-24563

MEDIUM CVSS 6.1 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24577 - Coming Soon And Maintenance Mode Plugin

The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.

PLUGIN Coming Soon And Maintenance Mode

CVE-2021-24577

MEDIUM CVSS 5.4 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24545 - Wp Html Author Bio Plugin

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

PLUGIN Wp Html Author Bio

CVE-2021-24545

MEDIUM CVSS 5.4 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24656 - Simple Social Media Share Buttons Plugin

The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Simple Social Media Share Buttons

CVE-2021-24656

MEDIUM CVSS 4.8 2021-10-11
Threat Entry Updated 2025-02-14

CVE-2021-39351 - Wp Bannerize Plugin

The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2.

PLUGIN Wp Bannerize

CVE-2021-39351

MEDIUM CVSS 6.5 2021-10-06
Threat Entry Updated 2025-02-14

CVE-2021-39350 - Fv Flowplayer Video Player Plugin

The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727.

PLUGIN Fv Flowplayer Video Player

CVE-2021-39350

MEDIUM CVSS 6.1 2021-10-06
Threat Entry Updated 2024-11-21

CVE-2021-39347 - Stripe For Woocommerce Plugin

The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes/admin/class-wc-stripe-admin-user-edit.php file that makes it possible for attackers to configure their account to use other site users unique STRIPE identifier and make purchases with their payment accounts. This affects versions 3.0.0 - 3.3.9.

PLUGIN Stripe For Woocommerce

CVE-2021-39347

MEDIUM CVSS 4.3 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24678 - Cm Tooltip Glossary Plugin

The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Cm Tooltip Glossary

CVE-2021-24678

MEDIUM CVSS 5.4 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24687 - Modern Events Calendar Lite Plugin

The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Modern Events Calendar Lite

CVE-2021-24687

MEDIUM CVSS 4.8 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24465 - Meow Gallery Plugin

The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manipulated in a way that could lead to data disclosure and arbitrary objects to be deserialized.

PLUGIN Meow Gallery

CVE-2021-24465

HIGH CVSS 8.1 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24676 - Better Find And Replace Plugin

The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Better Find And Replace

CVE-2021-24676

MEDIUM CVSS 6.1 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24654 - User Registration Plugin

The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their profile is viewed

PLUGIN User Registration

CVE-2021-24654

MEDIUM CVSS 5.4 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-24673 - Appointment Hour Booking Plugin

The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Appointment Hour Booking

CVE-2021-24673

MEDIUM CVSS 4.8 2021-10-04
Threat Entry Updated 2024-11-21

CVE-2021-39342 - Financial Plugin

The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and including, 1.4.8.

PLUGIN Financial

CVE-2021-39342

MEDIUM CVSS 5.3 2021-09-29
Threat Entry Updated 2024-11-21

CVE-2021-34636 - Woocommerce Sales Timers Plugin

The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.7.

PLUGIN Woocommerce Sales Timers

CVE-2021-34636

HIGH CVSS 8.8 2021-09-28
Threat Entry Updated 2024-11-21

CVE-2021-24666 - Podlove Podcast Publisher Plugin

The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.

PLUGIN Podlove Podcast Publisher

CVE-2021-24666

CRITICAL CVSS 9.8 2021-09-27
Scroll to top