Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 16061-16080 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-24445 - My Site Audit Plugin

The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN My Site Audit

CVE-2021-24445

MEDIUM CVSS 5.5 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24534 - Phonetrack Meu Site Manager Plugin

The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before outputting it back in an attribute in the page, leading to a stored Cross-Site Scripting issue.

PLUGIN Phonetrack Meu Site Manager

CVE-2021-24534

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24526 - Drop Contact Form Builder Plugin

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Drop Contact Form Builder

CVE-2021-24526

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24512 - Video Posts Webcam Recorder Plugin

The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos.

PLUGIN Video Posts Webcam Recorder

CVE-2021-24512

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24471 - Youtube Embed Plugin

The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, leading to Stored XSS issues by 1. using w, h, controls, cc_lang, color, language, start, stop, or style parameter of youtube shortcode, 2. by using style, class, rel, target, width, height, or alt parameter of youtube_thumb shortcode, or 3. by embedding a video whose title or description contains XSS payload (if API key is configured).

PLUGIN Youtube Embed

CVE-2021-24471

MEDIUM CVSS 5.4 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24363 - Mobile Friendly Image Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images/SVG anywhere in the filesystem via a path traversal vector

PLUGIN Mobile Friendly Image Gallery

CVE-2021-24363

MEDIUM CVSS 4.9 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24519 - Vikrentcar Car Rental Management System Plugin

The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS payload in it, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Vikrentcar Car Rental Management System

CVE-2021-24519

MEDIUM CVSS 4.8 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24518 - Wpfront Notification Bar Plugin

The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Wpfront Notification Bar

CVE-2021-24518

MEDIUM CVSS 4.8 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24380 - Shantz Wordpress Qotd Plugin

The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values.

PLUGIN Shantz Wordpress Qotd

CVE-2021-24380

MEDIUM CVSS 4.3 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-24362 - Mobile Friendly Image Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issue

PLUGIN Mobile Friendly Image Gallery

CVE-2021-24362

MEDIUM CVSS 6.1 2021-08-16
Threat Entry Updated 2024-11-21

CVE-2021-34640 - Securimage Wp Fixed Plugin

The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.4.

PLUGIN Securimage Wp Fixed

CVE-2021-34640

MEDIUM CVSS 6.1 2021-08-11
Threat Entry Updated 2024-11-21

CVE-2021-34661 - Wp Fusion Lite Plugin

The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function found in the ~/includes/admin/logging/class-log-handler.php file which allows attackers to drop all logs for the plugin, in versions up to and including 3.37.18.

PLUGIN Wp Fusion Lite

CVE-2021-34661

MEDIUM CVSS 6.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-34660 - Wp Fusion Lite Plugin

The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.37.18.

PLUGIN Wp Fusion Lite

CVE-2021-34660

MEDIUM CVSS 6.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24521 - Add Sticky Fixed Buttons Plugin

The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.

PLUGIN Add Sticky Fixed Buttons

CVE-2021-24521

HIGH CVSS 7.2 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24522 - Before 3 Plugin

The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.

PLUGIN Before 3

CVE-2021-24522

MEDIUM CVSS 6.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24507 - Astra Pro Addon Plugin

The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

PLUGIN Astra Pro Addon

CVE-2021-24507

CRITICAL CVSS 9.8 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24499 - Workreap Plugin

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.

PLUGIN Workreap

CVE-2021-24499

CRITICAL CVSS 9.8 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24520 - Out Of Stock Message For Woocommerce Plugin

The Stock in & out WordPress plugin through 1.0.4 lacks proper sanitization before passing variables to an SQL request, making it vulnerable to SQL Injection attacks. Users with a role of contributor or higher can exploit this vulnerability.

PLUGIN Out Of Stock Message For Woocommerce

CVE-2021-24520

HIGH CVSS 8.8 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24501 - Workreap Plugin

The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.

PLUGIN Workreap

CVE-2021-24501

HIGH CVSS 8.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24500 - Workreap Plugin

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

PLUGIN Workreap

CVE-2021-24500

HIGH CVSS 8.1 2021-08-09
Scroll to top