Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15821-15840 of 16392 records
Threat Entry Updated 2025-07-01

CVE-2021-36875 - Ulisting Plugin

Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin – uListing: from n/a through 2.0.5.

PLUGIN Ulisting

CVE-2021-36875

MEDIUM CVSS 5.9 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24671 - Mx Time Zone Clocks Plugin

The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Mx Time Zone Clocks

CVE-2021-24671

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24670 - Before 4 Plugin

The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks

PLUGIN Before 4

CVE-2021-24670

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24660 - Gutenberg Blocks For Post Grid Plugin

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.

PLUGIN Gutenberg Blocks For Post Grid

CVE-2021-24660

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24661 - Gutenberg Blocks For Post Grid Plugin

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.

PLUGIN Gutenberg Blocks For Post Grid

CVE-2021-24661

MEDIUM CVSS 4.3 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24652 - Gutenberg Blocks For Post Grid Plugin

The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.

PLUGIN Gutenberg Blocks For Post Grid

CVE-2021-24652

MEDIUM CVSS 6.5 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24632 - Recipe Card Blocks By Wpzoom Plugin

The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Recipe Card Blocks By Wpzoom

CVE-2021-24632

MEDIUM CVSS 6.1 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24643 - Wp Map Block Plugin

The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Wp Map Block

CVE-2021-24643

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24634 - Recipe Card Blocks By Wpzoom Plugin

The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Recipe Card Blocks By Wpzoom

CVE-2021-24634

MEDIUM CVSS 5.4 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24610 - Before 2 Plugin

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

PLUGIN Before 2

CVE-2021-24610

MEDIUM CVSS 4.8 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24569 - Before 2 Plugin

The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as admin to perform Cross-Site Scripting even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24569

MEDIUM CVSS 4.8 2021-09-27
Threat Entry Updated 2024-11-21

CVE-2021-24633 - Countdown Block Plugin

The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

PLUGIN Countdown Block

CVE-2021-24633

MEDIUM CVSS 4.3 2021-09-27
Scroll to top