Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24854
The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : qr_redirector- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24826
The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html i... Read more
Affected Products : custom_content_shortcode- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24822
The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perfo... Read more
Affected Products : stylish_cost_calculator- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24821
The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost Calculator > Price Settings (which gets injected on the edit page as well as... Read more
Affected Products : cost_calculator- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24817
The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks... Read more
Affected Products : ultimate_nofollow- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24812
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.... Read more
Affected Products : betterlinks- Published: Nov. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24807
The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatical... Read more
Affected Products : support_board- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24759
The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, which could allow users with a role as low as Contributor to to perform Cross-Site Scripting attacks... Read more
Affected Products : pdf.js_viewer- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24760
The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.... Read more
Affected Products : pdf_viewer_block_for_gutenberg- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24745
The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks.... Read more
Affected Products : about_author_box- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24738
The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : logo_carousel- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24743
The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding posts to perform stored XSS.... Read more
Affected Products : podcast_subscribe_buttons- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24734
The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : compact_wp_audio_player- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24723
The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.... Read more
Affected Products : wp_reactions_lite- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24751
The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.... Read more
Affected Products : generateblocks- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24729
The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.... Read more
Affected Products : logo_showcase_with_slick_slider- Published: Nov. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24732
The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored C... Read more
Affected Products : dearflip- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24699
The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : easy_media_download- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24690
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.... Read more
Affected Products : chained_quiz- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24682
The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : cool_tag_cloud- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024