Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 501-519 of 519 records
Threat Entry Updated 2024-11-21

CVE-2021-24389 - Used In The Foodbakery Theme

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

THEME Used In The Foodbakery

CVE-2021-24389

MEDIUM CVSS 6.1 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24375 - View Ajax Handlers Of The Motor Theme

Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary files in the server file system, and to execute arbitrary php scripts found on the server file system. We found no vulnerability for uploading files with this theme, so any scripts to be executed must already be on the server file system.

THEME View Ajax Handlers Of The Motor

CVE-2021-24375

CRITICAL CVSS 9.8 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24387 - Wp Pro Real Estate 7 Theme

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

THEME Wp Pro Real Estate 7

CVE-2021-24387

MEDIUM CVSS 6.1 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24364 - Before 5 Theme

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

THEME Before 5

CVE-2021-24364

MEDIUM CVSS 6.1 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24342 - Before 8 Theme

The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.

THEME Before 8

CVE-2021-24342

MEDIUM CVSS 6.1 2021-06-07
Threat Entry Updated 2024-11-21

CVE-2021-24321 - Before 1 Theme

The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues

THEME Before 1

CVE-2021-24321

CRITICAL CVSS 9.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24318 - Before 1 Theme

The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.

THEME Before 1

CVE-2021-24318

MEDIUM CVSS 6.5 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24335 - Auto Mechanic Theme

The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue

THEME Auto Mechanic

CVE-2021-24335

MEDIUM CVSS 6.1 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24320 - Before 1 Theme

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameter in ints listing page, leading to reflected Cross-Site Scripting issues.

THEME Before 1

CVE-2021-24320

MEDIUM CVSS 6.1 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24319 - Before 1 Theme

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue

THEME Before 1

CVE-2021-24319

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24317 - Before 1 Theme

The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues

THEME Before 1

CVE-2021-24317

MEDIUM CVSS 6.1 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24297 - Before 2 Theme

The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.

THEME Before 2

CVE-2021-24297

MEDIUM CVSS 6.1 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24314 - Before 2 Theme

The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue

THEME Before 2

CVE-2021-24314

CRITICAL CVSS 9.8 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24270 - Dethemekit For Elementor

The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

THEME Dethemekit For Elementor

CVE-2021-24270

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24235 - Before 2 Theme

The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.

THEME Before 2

CVE-2021-24235

MEDIUM CVSS 6.1 2021-04-22
Threat Entry Updated 2024-11-21

CVE-2021-24220 - Focusblog By Thrive Themes

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using the Kraken…

THEME Focusblog By Thrive Themes

CVE-2021-24220

CRITICAL CVSS 9.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24219 - 1 And Rise By Thrive Themes

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, Luxe by…

THEME 1 And Rise By Thrive Themes

CVE-2021-24219

MEDIUM CVSS 5.3 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24154 - Theme Editor

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd

THEME Theme Editor

CVE-2021-24154

MEDIUM CVSS 4.9 2021-04-05
Scroll to top