Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,429
Critical1,034
High3,419
Medium11,703
Reset
Showing 16301-16320 of 16429 records
Threat Entry Updated 2024-11-21

CVE-2021-24250 - Easy Listing Directories For Wordpress Plugin

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.

PLUGIN Easy Listing Directories For Wordpress

CVE-2021-24250

MEDIUM CVSS 5.4 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24247 - Contact Form Check Tester Plugin

The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. The vendor decided to close the plugin.

PLUGIN Contact Form Check Tester

CVE-2021-24247

MEDIUM CVSS 5.4 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24246 - Workscout Core Plugin

The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues

PLUGIN Workscout Core

CVE-2021-24246

MEDIUM CVSS 5.4 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24243 - Before 4 Plugin

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.

PLUGIN Before 4

CVE-2021-24243

MEDIUM CVSS 5.4 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24251 - Easy Listing Directories For Wordpress Plugin

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)

PLUGIN Easy Listing Directories For Wordpress

CVE-2021-24251

MEDIUM CVSS 4.3 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24276 - Contact Form By Supsystic Plugin

The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

PLUGIN Contact Form By Supsystic

CVE-2021-24276

MEDIUM CVSS 6.1 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24275 - Popup By Supsystic Plugin

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

PLUGIN Popup By Supsystic

CVE-2021-24275

MEDIUM CVSS 6.1 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24274 - Ultimate Maps By Supsystic Plugin

The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

PLUGIN Ultimate Maps By Supsystic

CVE-2021-24274

MEDIUM CVSS 6.1 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24273 - Before 2 Plugin

The “Clever Addons for Elementor” WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 2

CVE-2021-24273

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24271 - Before 1 Plugin

The “Ultimate Addons for Elementor” WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24271

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24270 - Before 1 Plugin

The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24270

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24269 - Before 3 Plugin

The “Sina Extension for Elementor” WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 3

CVE-2021-24269

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24268 - Before 1 Plugin

The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24268

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24267 - Before 2 Plugin

The “All-in-One Addons for Elementor – WidgetKit” WordPress Plugin before 2.3.10 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 2

CVE-2021-24267

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24266 - Before 2 Plugin

The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 2

CVE-2021-24266

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24265 - Before 1 Plugin

The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24265

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24264 - Before 1 Plugin

The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24264

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24263 - Before 2 Plugin

The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 2

CVE-2021-24263

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24262 - Before 1 Plugin

The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24262

MEDIUM CVSS 5.4 2021-05-05
Scroll to top