Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2021-36880 - Ulisting Plugin
Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions
CVE-2021-36880
CVE-2021-36874 - Ulisting Plugin
Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions
CVE-2021-36874
CVE-2021-36841 - Yith Maintenance Mode Plugin
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions
CVE-2021-36841
CVE-2021-36875 - Ulisting Plugin
Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS.This issue affects Directory Listings WordPress plugin – uListing: from n/a through 2.0.5.
CVE-2021-36875
CVE-2021-36876 - Ulisting Plugin
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions
CVE-2021-36876
CVE-2021-24671 - Mx Time Zone Clocks Plugin
The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
CVE-2021-24671
CVE-2021-24670 - Before 4 Plugin
The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks
CVE-2021-24670
CVE-2021-24660 - Gutenberg Blocks For Post Grid Plugin
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.
CVE-2021-24660
CVE-2021-36877 - Ulisting Plugin
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions
CVE-2021-36877
CVE-2021-24661 - Gutenberg Blocks For Post Grid Plugin
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID.
CVE-2021-24661
CVE-2021-24652 - Gutenberg Blocks For Post Grid Plugin
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.
CVE-2021-24652
CVE-2021-24632 - Recipe Card Blocks By Wpzoom Plugin
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
CVE-2021-24632
CVE-2021-24659 - Gutenberg Blocks For Post Grid Plugin
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.
CVE-2021-24659
CVE-2021-24643 - Wp Map Block Plugin
The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
CVE-2021-24643
CVE-2021-24634 - Recipe Card Blocks By Wpzoom Plugin
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
CVE-2021-24634
CVE-2021-24610 - Before 2 Plugin
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.
CVE-2021-24610
CVE-2021-24569 - Before 2 Plugin
The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as admin to perform Cross-Site Scripting even when the unfiltered_html capability is disallowed.
CVE-2021-24569
CVE-2021-24633 - Countdown Block Plugin
The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.
CVE-2021-24633
CVE-2021-36878 - Ulisting Plugin
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions
CVE-2021-36878
CVE-2021-36873 - Iq Block Country Plugin
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions
CVE-2021-36873
