Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24699
The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : easy_media_download- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24690
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.... Read more
Affected Products : chained_quiz- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24682
The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : cool_tag_cloud- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24694
The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argu... Read more
Affected Products : simple_download_monitor- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24678
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : tooltip_glossary- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24671
The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : mx_time_zone_clocks- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24672
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : one_user_avatar- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24670
The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks... Read more
Affected Products : coolclock- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24665
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks... Read more
Affected Products : wp_video_lightbox- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24660
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.... Read more
Affected Products : postx_-_gutenberg_blocks_for_post_grid- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24685
The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (t... Read more
Affected Products : flat_preloader- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24640
The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks... Read more
Affected Products : gutenslider- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24659
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.... Read more
Affected Products : postx_-_gutenberg_blocks_for_post_grid- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24637
The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), alig... Read more
Affected Products : fonts- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24611
The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacke... Read more
Affected Products : keyword_meta- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24618
The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when savin... Read more
Affected Products : donate_with_qrcode- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24643
The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : wp_map_block- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24591
The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : highlight- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24615
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.... Read more
Affected Products : wechat_reward- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24603
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed... Read more
Affected Products : site_reviews- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024