Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,426
Critical1,034
High3,419
Medium11,703
Reset
Showing 16241-16260 of 16426 records
Threat Entry Updated 2024-11-21

CVE-2021-24317 - Listeo Plugin

The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues

PLUGIN Listeo

CVE-2021-24317

MEDIUM CVSS 6.1 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24316 - Mediumish Plugin

The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

PLUGIN Mediumish

CVE-2021-24316

MEDIUM CVSS 6.1 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24313 - Before 1 Plugin

The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads.

PLUGIN Before 1

CVE-2021-24313

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24309 - Input In The Weekly Schedule Plugin

The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the HTML tags and cause a stored XSS issue

PLUGIN Input In The Weekly Schedule

CVE-2021-24309

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24310 - Photo Gallery By 10web Mobile Friendly Image Gallery Plugin

The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard. This is due to an incomplete fix of CVE-2019-16117

PLUGIN Photo Gallery By 10web Mobile Friendly Image Gallery

CVE-2021-24310

MEDIUM CVSS 4.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24307 - All In One Seo Plugin

The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's configuration by uploading a backup .ini file in the section "Tool > Import/Export". However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution.

PLUGIN All In One Seo

CVE-2021-24307

HIGH CVSS 8.8 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24305 - Watcheezy Plugin

The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID option and is not sanitized.

PLUGIN Watcheezy

CVE-2021-24305

MEDIUM CVSS 6.1 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24300 - Slider Import Search Feature Of The Pickplugins Product Slider For Woocommerce

The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue

PLUGIN Slider Import Search Feature Of The Pickplugins Product Slider For Woocommerce

CVE-2021-24300

MEDIUM CVSS 6.1 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24297 - Goto Plugin

The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.

PLUGIN Goto

CVE-2021-24297

MEDIUM CVSS 6.1 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24294 - Log Ajax Action Of The Dsgvo All In One For Wp Plugin

The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to gain unauthorised access by using an XSS payload to create a rogue administrator account, which will be trigged when an administrator will view the logs.

PLUGIN Log Ajax Action Of The Dsgvo All In One For Wp

CVE-2021-24294

MEDIUM CVSS 6.1 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24308 - Learning Management System Plugin

The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.

PLUGIN Learning Management System

CVE-2021-24308

MEDIUM CVSS 5.4 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24306 - Before 2 Plugin

The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated reflected Cross-Site Scripting issue. Knowledge of the targeted username is required to exploit this, and attackers would then need to make the related logged in user open a malicious link.

PLUGIN Before 2

CVE-2021-24306

MEDIUM CVSS 5.4 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24302 - Hana Flv Player Plugin

The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.

PLUGIN Hana Flv Player

CVE-2021-24302

MEDIUM CVSS 5.4 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24301 - Hotjar Connecticator Plugin

The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly verified by the server and this vulnerability could only be exploited by administrator users.

PLUGIN Hotjar Connecticator

CVE-2021-24301

MEDIUM CVSS 5.4 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24332 - Before 2 Plugin

The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues

PLUGIN Before 2

CVE-2021-24332

MEDIUM CVSS 4.8 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24296 - Wp Customer Reviews Plugin

The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled

PLUGIN Wp Customer Reviews

CVE-2021-24296

MEDIUM CVSS 4.8 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24314 - Goto Plugin

The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue

PLUGIN Goto

CVE-2021-24314

CRITICAL CVSS 9.8 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24289 - Store Locator Plus Plugin

There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.

PLUGIN Store Locator Plus

CVE-2021-24289

HIGH CVSS 8.8 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24295 - Firewall By Cleantalk Plugin

It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.

PLUGIN Firewall By Cleantalk

CVE-2021-24295

HIGH CVSS 7.5 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24324 - All 404 Redirect To Homepage Plugin

The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site Scripting issues

PLUGIN All 404 Redirect To Homepage

CVE-2021-24324

MEDIUM CVSS 6.5 2021-05-17
Scroll to top