Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,426
Critical1,034
High3,419
Medium11,703
Reset
Showing 16261-16280 of 16426 records
Threat Entry Updated 2024-11-21

CVE-2021-24325 - Seo Redirection Plugin

The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.

PLUGIN Seo Redirection

CVE-2021-24325

MEDIUM CVSS 6.1 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24299 - Redi Restaurant Reservation Plugin

The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to make a restaurant reservation field called 'Comment' does not use proper input validation and can be used to store XSS payloads. The XSS payloads will be executed when the plugin user goes to the 'Upcoming' page, which is an external website…

PLUGIN Redi Restaurant Reservation

CVE-2021-24299

MEDIUM CVSS 6.1 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24290 - Store Locator Plus Plugin

There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.

PLUGIN Store Locator Plus

CVE-2021-24290

MEDIUM CVSS 6.1 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24326 - Tab Parameter Of The Settings Page Of The All 404 Redirect To Homepage Plugin

The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

PLUGIN Tab Parameter Of The Settings Page Of The All 404 Redirect To Homepage

CVE-2021-24326

MEDIUM CVSS 5.4 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24292 - Happy Addons For Elementor Plugin

The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag” parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a ‘save_builder’ request with the “heading_tag” set to “script”, and the actual “title” parameter set to JavaScript to be executed within the script tags added…

PLUGIN Happy Addons For Elementor

CVE-2021-24292

MEDIUM CVSS 5.4 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24327 - 301 Redirect Manager Plugin

The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads

PLUGIN 301 Redirect Manager

CVE-2021-24327

MEDIUM CVSS 4.8 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24315 - Donation Plugin And Fundraising Platform

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email settings, leading to authenticated (admin+) Stored XSS issues.

PLUGIN Donation Plugin And Fundraising Platform

CVE-2021-24315

MEDIUM CVSS 4.8 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24285 - Cars Seller Auto Classifieds Script Plugin

The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.

PLUGIN Cars Seller Auto Classifieds Script

CVE-2021-24285

CRITICAL CVSS 9.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24284 - Kaswara Plugin

The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.

PLUGIN Kaswara

CVE-2021-24284

CRITICAL CVSS 9.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24195 - Before 1 Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Before 1

CVE-2021-24195

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24194 - In The Login Protection Limit Failed Login Attempts Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN In The Login Protection Limit Failed Login Attempts

CVE-2021-24194

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24193 - In The Visitor Traffic Real Time Statistics Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN In The Visitor Traffic Real Time Statistics

CVE-2021-24193

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24192 - In The Tree Sitemap Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN In The Tree Sitemap

CVE-2021-24192

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24282 - In The Redirection For Contact Form 7 Plugin

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a form, and more.

PLUGIN In The Redirection For Contact Form 7

CVE-2021-24282

MEDIUM CVSS 6.3 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24291 - Mobile Friendly Image Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)

PLUGIN Mobile Friendly Image Gallery

CVE-2021-24291

MEDIUM CVSS 6.1 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24287 - Change Checkbox To Radio Buttons Plugin

The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

PLUGIN Change Checkbox To Radio Buttons

CVE-2021-24287

MEDIUM CVSS 6.1 2021-05-14
Scroll to top