Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24751
The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.... Read more
Affected Products : generateblocks- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24729
The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.... Read more
Affected Products : logo_showcase_with_slick_slider- Published: Nov. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24732
The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored C... Read more
Affected Products : dearflip- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24699
The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : easy_media_download- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24690
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.... Read more
Affected Products : chained_quiz- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24682
The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : cool_tag_cloud- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24694
The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argu... Read more
Affected Products : simple_download_monitor- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24678
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : tooltip_glossary- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24671
The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : mx_time_zone_clocks- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24672
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : one_user_avatar- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24670
The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks... Read more
Affected Products : coolclock- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24665
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks... Read more
Affected Products : wp_video_lightbox- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24660
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.... Read more
Affected Products : postx_-_gutenberg_blocks_for_post_grid- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24685
The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (t... Read more
Affected Products : flat_preloader- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24640
The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks... Read more
Affected Products : gutenslider- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24659
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.... Read more
Affected Products : postx_-_gutenberg_blocks_for_post_grid- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24637
The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), alig... Read more
Affected Products : fonts- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24611
The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacke... Read more
Affected Products : keyword_meta- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24618
The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when savin... Read more
Affected Products : donate_with_qrcode- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24643
The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : wp_map_block- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024