Latest CVE Feed
-
5.4
MEDIUMCVE-2021-25113
The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisation and escaping, it could also lead ... Read more
Affected Products : dropdown_menu_widget- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25106
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subsc... Read more
Affected Products : wplegalpages- Published: Feb. 07, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25090
The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in various functions related to AJAX actions, allowing any authenticated users, such as subscriber, to call them. Due to the lack of sanitisat... Read more
Affected Products : portfolio_gallery\,_product_catalog_-_grid_kit_portfolio- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25065
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.... Read more
Affected Products : smash_balloon_social_post_feed- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25067
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.... Read more
Affected Products : landing_page- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25057
The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings.... Read more
Affected Products : translation_exchange- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25048
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them... Read more
Affected Products : kingcomposer- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25018
The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation... Read more
Affected Products : ppom_for_woocommerce- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25046
The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.... Read more
Affected Products : modern_events_calendar_lite- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24988
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation ... Read more
Affected Products : wp_rss_aggregator- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24971
The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could ... Read more
Affected Products : wp_responsive_menu- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24927
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripti... Read more
- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24974
The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be... Read more
Affected Products : product_feed_pro_for_woocommerce- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24930
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue... Read more
Affected Products : bookly- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24950
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and... Read more
Affected Products : insight_core- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24958
The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_business_selected_account AJAX action, available to any authenticated user, and does not escape some of the settings. As a result, any ... Read more
Affected Products : meks_easy_photo_feed_widget- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24883
The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks... Read more
Affected Products : popup_anything- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24965
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with... Read more
Affected Products : five_star_restaurant_reservations- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24933
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting iss... Read more
Affected Products : dynamic_widgets- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24871
The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks... Read more
Affected Products : get_custom_field_values- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024