Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 16121-16140 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-24456 - Quiz Maker Plugin

The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard

PLUGIN Quiz Maker

CVE-2021-24456

HIGH CVSS 7.2 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24468 - Leaflet Map Plugin

The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues

PLUGIN Leaflet Map

CVE-2021-24468

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24464 - Playlist And Popup By Wpdevart Plugin

The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.

PLUGIN Playlist And Popup By Wpdevart

CVE-2021-24464

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24455 - Elearning And Online Course Solution Plugin

The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by users as low as Tutor Instructor. This lead to a Stored Cross-Site Scripting issue, which is triggered when viewing the Announcements list, and could result in privilege escalation when viewed by an admin.

PLUGIN Elearning And Online Course Solution

CVE-2021-24455

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24450 - Before 3 Plugin

The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and outputting them back in the page, allowing high privilege users such as admin to set JavaScript payloads in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Before 3

CVE-2021-24450

MEDIUM CVSS 4.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24448 - Profile Builder Plugin

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Profile Builder

CVE-2021-24448

MEDIUM CVSS 4.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24444 - Before 3 Plugin

The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.

PLUGIN Before 3

CVE-2021-24444

MEDIUM CVSS 4.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24430 - Pagespeed Optimization Suite Plugin

The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE

PLUGIN Pagespeed Optimization Suite

CVE-2021-24430

HIGH CVSS 7.2 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24443 - Before 1 Plugin

The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile. This could allow a low privilege user to gain unauthorised access to the admin side of the blog by targeting an admin, inducing them to view their profile with a malicious payload adding a rogue account for example.

PLUGIN Before 1

CVE-2021-24443

MEDIUM CVSS 5.4 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24428 - Yandex Turbo Plugin

The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving and outputing them in the admin dashboard, leading to an Authenticated Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed.

PLUGIN Yandex Turbo

CVE-2021-24428

MEDIUM CVSS 4.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24425 - Before 2 Plugin

The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered in the plugin's setting, as well as all front-page of the blog (when the Welcome bar is active)

PLUGIN Before 2

CVE-2021-24425

MEDIUM CVSS 4.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24371 - Import Feature Of The Rsvpmaker Plugin

The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could use that feature to scan the internal network via a SSRF attack.

PLUGIN Import Feature Of The Rsvpmaker

CVE-2021-24371

LOW CVSS 2.7 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-34629 - Sendgrid Plugin

The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistic for a WordPress multi-site main site, in versions up to and including 1.11.8.

PLUGIN Sendgrid

CVE-2021-34629

MEDIUM CVSS 4.3 2021-07-30
Threat Entry Updated 2024-11-21

CVE-2021-32790 - Woocommerce Plugin

Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `/wp-json/wc/v3/webhooks`, `/wp-json/wc/v2/webhooks` and other webhook listing API. Read-only SQL queries can be executed using this exploit, while data will not be returned, by carefully crafting `search` parameter information can be disclosed using timing and related attacks. Version 3.3.6 is the earliest version of Woocommerce with a…

PLUGIN Woocommerce

CVE-2021-32790

MEDIUM CVSS 4.9 2021-07-26
Threat Entry Updated 2024-11-21

CVE-2021-34619 - Stock Manager For Woocommerce Plugin

The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.

PLUGIN Stock Manager For Woocommerce

CVE-2021-34619

HIGH CVSS 8.8 2021-07-21
Threat Entry Updated 2024-11-21

CVE-2021-3135 - Newspaper Plugin

An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.

PLUGIN Newspaper

CVE-2021-3135

MEDIUM CVSS 6.1 2021-07-19
Threat Entry Updated 2024-11-21

CVE-2021-24453 - Include Me Plugin

The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to Remote Code Execution (RCE) of the system due to log poisoning and therefore potentially a full compromise of the underlying structure

PLUGIN Include Me

CVE-2021-24453

HIGH CVSS 8.8 2021-07-19
Threat Entry Updated 2024-11-21

CVE-2021-24452 - W3 Total Cache Plugin

The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

PLUGIN W3 Total Cache

CVE-2021-24452

MEDIUM CVSS 6.1 2021-07-19
Threat Entry Updated 2024-11-21

CVE-2021-24436 - W3 Total Cache Plugin

The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

PLUGIN W3 Total Cache

CVE-2021-24436

MEDIUM CVSS 6.1 2021-07-19
Threat Entry Updated 2024-11-21

CVE-2021-24447 - Wp Image Zoom Plugin

The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() function, leading to a local file inclusion issue in the admin dashboard

PLUGIN Wp Image Zoom

CVE-2021-24447

MEDIUM CVSS 5.3 2021-07-19
Scroll to top