Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,429
Critical1,034
High3,419
Medium11,703
Reset
Showing 16341-16360 of 16429 records
Threat Entry Updated 2024-11-21

CVE-2021-24230 - Ck Scan Team Identified A Cross Site Request Forgery Vulnerability In The Patreon Plugin

The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user metadata on the victim’s account once visited. If exploited, this bug can be used to overwrite the “wp_capabilities” meta, which contains the affected user account’s roles and privileges. Doing this would essentially lock them out of the site, blocking them from accessing paid content.

PLUGIN Ck Scan Team Identified A Cross Site Request Forgery Vulnerability In The Patreon

CVE-2021-24230

HIGH CVSS 8.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24231 - Ck Scan Team Identified A Cross Site Request Forgery Vulnerability In The Patreon Plugin

The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconnect the site from Patreon by visiting a specially crafted link.

PLUGIN Ck Scan Team Identified A Cross Site Request Forgery Vulnerability In The Patreon

CVE-2021-24231

MEDIUM CVSS 6.5 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24223 - N5 Upload Form Plugin

The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case of misconfigured servers with Directory listing enabled, accessing it is trivial.

PLUGIN N5 Upload Form

CVE-2021-24223

CRITICAL CVSS 9.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24222 - Wp Curriculo Vitae Free Plugin

The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The form allows unauthenticated user to register and submit files for their profile picture as well as resume, without any file extension restriction, leading to RCE.

PLUGIN Wp Curriculo Vitae Free

CVE-2021-24222

CRITICAL CVSS 9.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24215 - Proper Access Control Vulnerability Was Discovered In The Controlled Admin Access Plugin

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

PLUGIN Proper Access Control Vulnerability Was Discovered In The Controlled Admin Access

CVE-2021-24215

CRITICAL CVSS 9.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24220 - Rise Plugin

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken…

PLUGIN Rise

CVE-2021-24220

CRITICAL CVSS 9.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24224 - Easy Form Builder By Bitware Plugin

The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing low privilege users to upload arbitrary files, leading to RCE.

PLUGIN Easy Form Builder By Bitware

CVE-2021-24224

HIGH CVSS 8.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24221 - Before 7 Plugin

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this shortcode in post or pages being author, such user could gain unauthorised access to the DBMS. If the shortcode (without the id attribute) is embed on a public page or post, then unauthenticated users could exploit the injection.

PLUGIN Before 7

CVE-2021-24221

HIGH CVSS 8.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24218 - Settings Ajax Actions Of The Facebook For Plugin

The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.

PLUGIN Settings Ajax Actions Of The Facebook For

CVE-2021-24218

HIGH CVSS 8.8 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24217 - Action Function Of The Facebook For Plugin

The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability. There was also a useable magic method in the plugin that could be used to achieve remote code execution.

PLUGIN Action Function Of The Facebook For

CVE-2021-24217

HIGH CVSS 8.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24227 - Jetpack Scan Team Identified A Local File Disclosure Vulnerability In The Patreon Plugin

The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.

PLUGIN Jetpack Scan Team Identified A Local File Disclosure Vulnerability In The Patreon

CVE-2021-24227

HIGH CVSS 7.5 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24226 - In The Accessally Plugin

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.

PLUGIN In The Accessally

CVE-2021-24226

HIGH CVSS 7.5 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24200 - Table Charts Premium Plugin

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'length' HTTP POST parameter. This allows an attacker to access all the data in the database and obtain access to the WordPress application.

PLUGIN Table Charts Premium

CVE-2021-24200

MEDIUM CVSS 6.5 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24213 - Donation Plugin And Fundraising Platform

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.

PLUGIN Donation Plugin And Fundraising Platform

CVE-2021-24213

MEDIUM CVSS 6.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24225 - Advanced Booking Calendar Plugin

The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue

PLUGIN Advanced Booking Calendar

CVE-2021-24225

MEDIUM CVSS 5.4 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24219 - Thrive Apprentice Plugin

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, Luxe by…

PLUGIN Thrive Apprentice

CVE-2021-24219

MEDIUM CVSS 5.3 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24198 - Table Charts Premium Plugin

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to delete the data of another user that are present in the same table through id_key and id_val parameters. By exploiting this issue an attacker is able to delete the data of all users in the same table.

PLUGIN Table Charts Premium

CVE-2021-24198

HIGH CVSS 8.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24197 - Table Charts Premium Plugin

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user permissions on the table through formdata[wdt_ID] parameter. By exploiting this issue an attacker is able to access and manage the data of all users in the same table.

PLUGIN Table Charts Premium

CVE-2021-24197

HIGH CVSS 8.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24199 - Table Charts Premium Plugin

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'start' HTTP POST parameter. This allows an attacker to access all the data in the database and obtain access to the WordPress application.

PLUGIN Table Charts Premium

CVE-2021-24199

MEDIUM CVSS 6.5 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24212 - Woocommerce Help Scout Plugin

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

PLUGIN Woocommerce Help Scout

CVE-2021-24212

CRITICAL CVSS 9.8 2021-04-05
Scroll to top