Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,423
Critical1,034
High3,417
Medium11,702
Reset
Showing 16161-16180 of 16423 records
Threat Entry Updated 2024-11-21

CVE-2021-34623 - Profilepress Plugin

A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

PLUGIN Profilepress

CVE-2021-34623

CRITICAL CVSS 9.8 2021-07-07
Threat Entry Updated 2024-11-21

CVE-2021-34622 - Profilepress Plugin

A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. .

PLUGIN Profilepress

CVE-2021-34622

CRITICAL CVSS 9.8 2021-07-07
Threat Entry Updated 2024-11-21

CVE-2021-34621 - Profilepress Plugin

A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .

PLUGIN Profilepress

CVE-2021-34621

CRITICAL CVSS 9.8 2021-07-07
Threat Entry Updated 2024-11-21

CVE-2021-34620 - WP Fluent Forms Plugin

The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions

PLUGIN WP Fluent Forms

CVE-2021-34620

HIGH CVSS 8.8 2021-07-07
Threat Entry Updated 2024-11-21

CVE-2021-34625 - Wp Upload Restriction Plugin

A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affects versions 2.2.3 and prior.

PLUGIN Wp Upload Restriction

CVE-2021-34625

MEDIUM CVSS 6.4 2021-07-07
Threat Entry Updated 2024-11-21

CVE-2021-34627 - Wp Upload Restriction Plugin

A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

PLUGIN Wp Upload Restriction

CVE-2021-34627

MEDIUM CVSS 4.3 2021-07-07
Threat Entry Updated 2024-11-21

CVE-2021-34626 - Wp Upload Restriction Plugin

A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.

PLUGIN Wp Upload Restriction

CVE-2021-34626

MEDIUM CVSS 4.3 2021-07-07
Threat Entry Updated 2024-11-21

CVE-2021-20780 - Wordpress Currency Switcher Plugin

Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

PLUGIN Wordpress Currency Switcher

CVE-2021-20780

HIGH CVSS 8.8 2021-07-07
Threat Entry Updated 2024-11-21

CVE-2021-20779 - Wp Html Mail Plugin

Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

PLUGIN Wp Html Mail

CVE-2021-20779

HIGH CVSS 8.8 2021-07-07
Threat Entry Updated 2024-11-21

CVE-2021-24451 - Export Users With Meta Plugin

The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection.

PLUGIN Export Users With Meta

CVE-2021-24451

HIGH CVSS 7.2 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24405 - Easy Cookies Policy Plugin

The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. If users can't register, this can be done through CSRF. Furthermore, the cookie banner setting is not sanitised or validated before being output in all pages of the frontend and the backend settings one, leading to a Stored Cross-Site Scripting issue.

PLUGIN Easy Cookies Policy

CVE-2021-24405

MEDIUM CVSS 6.5 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24407 - Jannah Plugin

The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.

PLUGIN Jannah

CVE-2021-24407

MEDIUM CVSS 6.1 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24406 - Wpforo Forum Plugin

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)

PLUGIN Wpforo Forum

CVE-2021-24406

MEDIUM CVSS 6.1 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24389 - Wp Foodbakery Plugin

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

PLUGIN Wp Foodbakery

CVE-2021-24389

MEDIUM CVSS 6.1 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24494 - Wp Offload Ses Lite Plugin

The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admin dashboard, such as the email's id, subject and recipient, which could lead to Stored Cross-Site Scripting issues when an attacker can control any of these fields, like the subject when filling a contact form for example. The XSS will be executed in the context of a logged in admin viewing the Activity tab of the plugin.

PLUGIN Wp Offload Ses Lite

CVE-2021-24494

MEDIUM CVSS 5.4 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24384 - Load Ajax Action Of The Joomsport Plugin

The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this, other installed plugins could, which might lead to more severe issues such as RCE

PLUGIN Load Ajax Action Of The Joomsport

CVE-2021-24384

CRITICAL CVSS 9.8 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24375 - Motor Plugin

Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary files in the server file system, and to execute arbitrary php scripts found on the server file system. We found no vulnerability for uploading files with this theme, so any scripts to be executed must already be on the server file system.

PLUGIN Motor

CVE-2021-24375

CRITICAL CVSS 9.8 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24387 - Real Estate 7 Plugin

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

PLUGIN Real Estate 7

CVE-2021-24387

MEDIUM CVSS 6.1 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24388 - In The Vikrentcar Car Rental Management System Plugin

In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields that the users will have to fill in before saving the order. However, the field name is not sanitised or escaped before being output back in the page, leading to a stored Cross-Site Scripting issue. There is also no CSRF check done before saving the setting, allowing attackers to make a logged in admin set arbitrary Custom Fields, including one with XSS payload in it.

PLUGIN In The Vikrentcar Car Rental Management System

CVE-2021-24388

MEDIUM CVSS 5.4 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24386 - Wp Svg Images Plugin

The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege users such as author+ to upload a malicious SVG and then perform XSS attacks by inducing another user to access the file directly. In v3.4, the plugin restricted such upload to editors and admin, with an option to also allow author to do so. The description of the plugin has also been updated with a security warning as upload of such content is intended.

PLUGIN Wp Svg Images

CVE-2021-24386

MEDIUM CVSS 5.4 2021-07-06
Scroll to top