Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,426
Critical1,034
High3,419
Medium11,703
Reset
Showing 16201-16220 of 16426 records
Threat Entry Updated 2024-11-21

CVE-2021-24368 - Exam And Survey Plugin

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link

PLUGIN Exam And Survey

CVE-2021-24368

MEDIUM CVSS 6.1 2021-06-20
Threat Entry Updated 2024-11-21

CVE-2021-24360 - Before 1 Plugin

The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks

PLUGIN Before 1

CVE-2021-24360

MEDIUM CVSS 6.5 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24382 - Smart Slider Plugin

The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin's functionality, in which case, privilege escalation could be performed.

PLUGIN Smart Slider

CVE-2021-24382

MEDIUM CVSS 5.4 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24356 - In The Simple 301 Redirects By Betterlinks Plugin

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.

PLUGIN In The Simple 301 Redirects By Betterlinks

CVE-2021-24356

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24354 - Ficient Nonce Check On The Ajax Action In The Simple 301 Redirects By Betterlinks Plugin

A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.

PLUGIN Ficient Nonce Check On The Ajax Action In The Simple 301 Redirects By Betterlinks

CVE-2021-24354

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24347 - Document Manager Plugin

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

PLUGIN Document Manager

CVE-2021-24347

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24341 - When Deleting A Date In The Xllentech English Islamic Calendar Plugin

When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement, leading to SQL injection.

PLUGIN When Deleting A Date In The Xllentech English Islamic Calendar

CVE-2021-24341

HIGH CVSS 8.8 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24348 - Add Fixed Side Buttons Plugin

The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issue

PLUGIN Add Fixed Side Buttons

CVE-2021-24348

HIGH CVSS 7.2 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24345 - Sendit Plugin

The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.

PLUGIN Sendit

CVE-2021-24345

MEDIUM CVSS 6.6 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24351 - Post Ajax Action Of The Plus Addons For Elementor Page Builder Plugin

The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)

PLUGIN Post Ajax Action Of The Plus Addons For Elementor Page Builder

CVE-2021-24351

MEDIUM CVSS 6.1 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24350 - Visitors Online Plugin

The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display the user's user agent string without validation or encoding within the WordPress admin panel.

PLUGIN Visitors Online

CVE-2021-24350

MEDIUM CVSS 6.1 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24349 - Gallery From Files Plugin

This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the attack could also be performed via such vector.

PLUGIN Gallery From Files

CVE-2021-24349

MEDIUM CVSS 6.1 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24357 - Before 2 Plugin

In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output in the page where the gallery is embed, leading to a stored Cross-Site Scripting issue.

PLUGIN Before 2

CVE-2021-24357

MEDIUM CVSS 5.4 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24346 - Stock In Out Plugin

The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being contributor. The srch POST parameter is not validated, sanitised or escaped before using it in the echo statement, leading to a reflected XSS issue

PLUGIN Stock In Out

CVE-2021-24346

MEDIUM CVSS 5.4 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24359 - Plus Addons For Elementor Page Builder Plugin

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password email to a registered user on behalf of the WordPress site. Such issue could be chained with an open redirect (CVE-2021-24358) in version below 4.1.10, to include a crafted password reset link in the email, which would lead to an account takeover.

PLUGIN Plus Addons For Elementor Page Builder

CVE-2021-24359

MEDIUM CVSS 5.3 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24355 - In The Simple 301 Redirects By Betterlinks Plugin

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.

PLUGIN In The Simple 301 Redirects By Betterlinks

CVE-2021-24355

MEDIUM CVSS 4.3 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-29504 - Wp Cli Plugin

WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI version 0.12.0 and later allows remote attackers able to intercept the communication to remotely disable the certificate verification on WP-CLI side, gaining full control over the communication content, including the ability to impersonate update servers and push malicious updates towards WordPress instances controlled by the vulnerable WP-CLI agent, or push malicious updates toward WP-CLI itself. The vulnerability stems from the fact that the default behavior of `WP_CLI\Utils\http_request()` when encountering a TLS handshake error…

PLUGIN Wp Cli

CVE-2021-29504

CRITICAL CVSS 9.1 2021-06-07
Scroll to top