Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,417
Critical1,032
High3,413
Medium11,702
Reset
Showing 15901-15920 of 16417 records
Threat Entry Updated 2024-11-21

CVE-2021-24583 - Timetable And Event Schedule Plugin

The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be performed via CSRF against a logged in with such capability

PLUGIN Timetable And Event Schedule

CVE-2021-24583

MEDIUM CVSS 4.3 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24399 - Sorter Plugin

The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

PLUGIN Sorter

CVE-2021-24399

HIGH CVSS 7.2 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24398 - Responsive 3d Slider Plugin

The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query is ran twice.

PLUGIN Responsive 3d Slider

CVE-2021-24398

HIGH CVSS 7.2 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24397 - Microcopy Plugin

The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

PLUGIN Microcopy

CVE-2021-24397

HIGH CVSS 7.2 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-24396 - Gseor Plugin

A pageid GET parameter of the GSEOR – WordPress SEO Plugin WordPress plugin through 1.3 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

PLUGIN Gseor

CVE-2021-24396

HIGH CVSS 7.2 2021-09-20
Threat Entry Updated 2024-11-21

CVE-2021-39327 - Bulletproof Security Plugin

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

PLUGIN Bulletproof Security

CVE-2021-39327

MEDIUM CVSS 5.3 2021-09-17
Threat Entry Updated 2024-11-21

CVE-2021-24728 - Paid Member Subscriptions Plugin

The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.

PLUGIN Paid Member Subscriptions

CVE-2021-24728

HIGH CVSS 8.8 2021-09-13
Threat Entry Updated 2026-01-16

CVE-2021-24727 - Before 6 Plugin

The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections

PLUGIN Before 6

CVE-2021-24727

HIGH CVSS 8.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24726 - Wp Simple Booking Calendar Plugin

The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue

PLUGIN Wp Simple Booking Calendar

CVE-2021-24726

HIGH CVSS 8.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24724 - Before 2 Plugin

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s

PLUGIN Before 2

CVE-2021-24724

MEDIUM CVSS 5.4 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24620 - Simple E Commerce Shopping Cart Plugin

The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PHP to be uploaded by an administrator. Furthermore, as there is no CSRF in place, attackers could also make a logged admin upload a malicious PHP file, which would lead to RCE

PLUGIN Simple E Commerce Shopping Cart

CVE-2021-24620

HIGH CVSS 8.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24623 - Elite Support Helpdesk Plugin

The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape form values before saving to the database or when outputting, which allows high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Elite Support Helpdesk

CVE-2021-24623

MEDIUM CVSS 4.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24621 - Wp Courses Lms Plugin

The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capability is disallowed, which could lead to Stored Cross-Site Scripting issues

PLUGIN Wp Courses Lms

CVE-2021-24621

MEDIUM CVSS 4.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24619 - Per Page Add To Head Plugin

The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.

PLUGIN Per Page Add To Head

CVE-2021-24619

MEDIUM CVSS 4.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24614 - Book Appointment Online Plugin

The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Book Appointment Online

CVE-2021-24614

MEDIUM CVSS 4.8 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24560 - Software License Manager Plugin

The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

PLUGIN Software License Manager

CVE-2021-24560

MEDIUM CVSS 6.1 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24605 - Custom Post View Generator Plugin

The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue

PLUGIN Custom Post View Generator

CVE-2021-24605

MEDIUM CVSS 5.4 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24523 - Daily Prayer Time Plugin

The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputting them in the page, leading to Authenticated Stored Cross-Site Scripting issues.

PLUGIN Daily Prayer Time

CVE-2021-24523

MEDIUM CVSS 5.4 2021-09-13
Threat Entry Updated 2024-11-21

CVE-2021-24586 - Per Page Add To Head Plugin

The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned by the plugin), this could lead to Stored XSS issue which will be triggered either in the backend, frontend or both depending on the payload used.

PLUGIN Per Page Add To Head

CVE-2021-24586

MEDIUM CVSS 4.3 2021-09-13
Scroll to top