Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,429
Critical1,034
High3,419
Medium11,703
Reset
Showing 16281-16300 of 16429 records
Threat Entry Updated 2024-11-21

CVE-2021-24291 - Mobile Friendly Image Gallery Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)

PLUGIN Mobile Friendly Image Gallery

CVE-2021-24291

MEDIUM CVSS 6.1 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24287 - Change Checkbox To Radio Buttons Plugin

The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

PLUGIN Change Checkbox To Radio Buttons

CVE-2021-24287

MEDIUM CVSS 6.1 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24277 - Rss For Yandex Turbo Plugin

The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settings tab before outputting them back in the page, leading to authenticated stored Cross-Site Scripting issues

PLUGIN Rss For Yandex Turbo

CVE-2021-24277

MEDIUM CVSS 5.4 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24191 - Site Under Construction Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Site Under Construction

CVE-2021-24191

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24190 - In The Woocommerce Conditional Marketing Mailer Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN In The Woocommerce Conditional Marketing Mailer

CVE-2021-24190

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24189 - Google Recaptcha For Admin Login Page Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Google Recaptcha For Admin Login Page

CVE-2021-24189

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24188 - No Right Click Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN No Right Click

CVE-2021-24188

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24236 - Imagements Plugin

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

PLUGIN Imagements

CVE-2021-24236

CRITICAL CVSS 9.8 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24253 - Classyfrieds Plugin

The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the content-type in the request. This allows any authenticated user to upload arbitrary PHP files via the Add Listing feature of the plugin, leading to RCE.

PLUGIN Classyfrieds

CVE-2021-24253

HIGH CVSS 8.8 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24179 - Easy Listing Directories For Wordpress Plugin

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE.

PLUGIN Easy Listing Directories For Wordpress

CVE-2021-24179

HIGH CVSS 8.8 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24178 - Easy Listing Directories For Wordpress Plugin

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.

PLUGIN Easy Listing Directories For Wordpress

CVE-2021-24178

HIGH CVSS 8.8 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24254 - College Publisher Import Plugin

The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload arbitrary files, such as PHP, leading to RCE. Due to the lack of CSRF check, the issue could also be exploited via a CSRF attack.

PLUGIN College Publisher Import

CVE-2021-24254

HIGH CVSS 7.2 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24252 - Event Banner Plugin

The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload arbitrary files, such as .exe, .php, or others executable, leading to RCE. Due to the lack of CSRF check, the issue can also be used via such vector to achieve the same result, or via a LFI as authorisation checks are missing (but would require WP to be loaded)

PLUGIN Event Banner

CVE-2021-24252

HIGH CVSS 7.2 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24248 - Easy Listing Directories For Wordpress Plugin

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE

PLUGIN Easy Listing Directories For Wordpress

CVE-2021-24248

HIGH CVSS 7.2 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24249 - Easy Listing Directories For Wordpress Plugin

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses etc

PLUGIN Easy Listing Directories For Wordpress

CVE-2021-24249

MEDIUM CVSS 6.5 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24244 - Before 4 Plugin

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).

PLUGIN Before 4

CVE-2021-24244

MEDIUM CVSS 6.5 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24245 - Stop Spammers Plugin

The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

PLUGIN Stop Spammers

CVE-2021-24245

MEDIUM CVSS 6.1 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24214 - Openid Connect Generic Client Plugin

The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.

PLUGIN Openid Connect Generic Client

CVE-2021-24214

MEDIUM CVSS 6.1 2021-05-06
Scroll to top