Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,392
Critical1,031
High3,411
Medium11,693
Reset
Showing 15841-15860 of 16392 records
Threat Entry Updated 2024-11-21

CVE-2021-34647 - Ninja Forms Plugin

The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information.

PLUGIN Ninja Forms

CVE-2021-34647

MEDIUM CVSS 6.5 2021-09-22
Threat Entry Updated 2024-11-21

CVE-2021-34648 - Ninja Forms Plugin

The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.

PLUGIN Ninja Forms

CVE-2021-34648

MEDIUM CVSS 6.4 2021-09-22
Threat Entry Updated 2024-11-21

CVE-2021-39339 - Telefication Plugin

The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file due to a user-supplied URL request value that gets called by a curl requests. This affects versions up to, and including, 1.8.0.

PLUGIN Telefication

CVE-2021-39339

MEDIUM CVSS 5.8 2021-09-22
Threat Entry Updated 2024-11-21

CVE-2021-34650 - Smart Id Plugin

The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.6.

PLUGIN Smart Id

CVE-2021-34650

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-39325 - Optinmonster Plugin

The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.6.0.

PLUGIN Optinmonster

CVE-2021-39325

MEDIUM CVSS 6.1 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24741 - Support Board Plugin

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

PLUGIN Support Board

CVE-2021-24741

CRITICAL CVSS 9.8 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24638 - Before 4 Plugin

The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

PLUGIN Before 4

CVE-2021-24638

CRITICAL CVSS 9.1 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24639 - Before 4 Plugin

The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.

PLUGIN Before 4

CVE-2021-24639

HIGH CVSS 8.1 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24636 - Print My Blog Plugin

The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link

PLUGIN Print My Blog

CVE-2021-24636

HIGH CVSS 8.1 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24663 - Simple Schools Staff Directory Plugin

The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitrary file like PHP, leading to RCE

PLUGIN Simple Schools Staff Directory

CVE-2021-24663

HIGH CVSS 7.2 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24657 - Limit Login Attempts Plugin

The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.

PLUGIN Limit Login Attempts

CVE-2021-24657

MEDIUM CVSS 6.1 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24640 - Gutenslider Plugin

The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

PLUGIN Gutenslider

CVE-2021-24640

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24637 - Google Fonts Typography Plugin

The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

PLUGIN Google Fonts Typography

CVE-2021-24637

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24635 - Visual Link Preview Plugin

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

PLUGIN Visual Link Preview

CVE-2021-24635

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24618 - Donate With Qrcode Plugin

The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.

PLUGIN Donate With Qrcode

CVE-2021-24618

MEDIUM CVSS 5.4 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24613 - Post Views Counter Plugin

The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed

PLUGIN Post Views Counter

CVE-2021-24613

MEDIUM CVSS 4.8 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24606 - Availability Calendar Plugin

The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+

PLUGIN Availability Calendar

CVE-2021-24606

HIGH CVSS 8.8 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24404 - Wp Board Plugin

The options.php file of the WP-Board WordPress plugin through 1.1 beta accepts a postid parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query ran twice.

PLUGIN Wp Board

CVE-2021-24404

HIGH CVSS 8.8 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24511 - Ajax Functionality In The Product Feed On Woocommerce Plugin

The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

PLUGIN Ajax Functionality In The Product Feed On Woocommerce

CVE-2021-24511

HIGH CVSS 7.2 2021-09-20
Scroll to top