Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,429
Critical1,034
High3,419
Medium11,703
Reset
Showing 16381-16400 of 16429 records
Threat Entry Updated 2024-11-21

CVE-2021-24180 - Unvalidated Input And Lack Of Output Encoding Within The Related Posts For Plugin

Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.

PLUGIN Unvalidated Input And Lack Of Output Encoding Within The Related Posts For

CVE-2021-24180

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2025-03-24

CVE-2021-24177 - Before 7 Plugin

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

PLUGIN Before 7

CVE-2021-24177

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24176 - Jh 404 Logger Plugin

The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.

PLUGIN Jh 404 Logger

CVE-2021-24176

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-25

CVE-2021-24171 - Woocommerce Upload Files Plugin

The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the "wcuf_file_name" parameter. It was also possible to perform a double extension attack and upload files to a different location via path traversal using the "wcuf_current_upload_session_id" parameter.

PLUGIN Woocommerce Upload Files

CVE-2021-24171

CRITICAL CVSS 9.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24163 - Drag And Drop Form Builder For Wordpress Plugin

The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin.

PLUGIN Drag And Drop Form Builder For Wordpress

CVE-2021-24163

HIGH CVSS 8.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24162 - Responsive Menu Plugin

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

PLUGIN Responsive Menu

CVE-2021-24162

HIGH CVSS 8.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24161 - Responsive Menu Plugin

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.

PLUGIN Responsive Menu

CVE-2021-24161

HIGH CVSS 8.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24160 - Responsive Menu Plugin

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These files could then be accessed via the front end of the site to trigger remote code execution and ultimately allow an attacker to execute commands to further infect a WordPress site.

PLUGIN Responsive Menu

CVE-2021-24160

HIGH CVSS 8.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24159 - Contact Form 7 Plugin

Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or attachment, then the request could be sent and the CSS settings would be successfully updated to include malicious JavaScript.

PLUGIN Contact Form 7

CVE-2021-24159

HIGH CVSS 8.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24170 - Users In The User Profile Picture Plugin

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

PLUGIN Users In The User Profile Picture

CVE-2021-24170

HIGH CVSS 7.5 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24173 - Vm Backups Plugin

The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.

PLUGIN Vm Backups

CVE-2021-24173

MEDIUM CVSS 6.1 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24165 - In The Ninja Forms Contact Form Plugin

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

PLUGIN In The Ninja Forms Contact Form

CVE-2021-24165

MEDIUM CVSS 6.1 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24168 - Easy Contact Form Pro Plugin

The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and editor) to perform XSS attacks against high privilege ones like administrator.

PLUGIN Easy Contact Form Pro

CVE-2021-24168

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24166 - Drag And Drop Form Builder For Wordpress Plugin

The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.

PLUGIN Drag And Drop Form Builder For Wordpress

CVE-2021-24166

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24172 - Vm Backups Plugin

The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .

PLUGIN Vm Backups

CVE-2021-24172

MEDIUM CVSS 4.3 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24164 - In The Ninja Forms Contact Form Plugin

In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

PLUGIN In The Ninja Forms Contact Form

CVE-2021-24164

MEDIUM CVSS 4.3 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24150 - Before 2 Plugin

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

PLUGIN Before 2

CVE-2021-24150

HIGH CVSS 7.5 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24155 - Backup Guard Plugin

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

PLUGIN Backup Guard

CVE-2021-24155

HIGH CVSS 7.2 2021-04-05
Scroll to top