Latest CVE Feed
-
9.8
CRITICALCVE-2021-24949
The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL statement, which could lead to SQL injection... Read more
Affected Products : the_plus_addons_for_elementor- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24857
The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.... Read more
Affected Products : totop_link- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24863
The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection... Read more
Affected Products : block_and_stop_bad_bots- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24849
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections... Read more
- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24867
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. Howe... Read more
Affected Products : ultimate-form-builder-lite accesspress_basic bingle bloger doko enlighten fotography parallaxsome punte revolve +83 more products- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24866
The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion... Read more
Affected Products : wp_data_access- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24827
The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue... Read more
Affected Products : asgaros_forum- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24731
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endp... Read more
Affected Products : pie_register- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24666
The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both param... Read more
Affected Products : podlove_podcast_publisher- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24551
The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue... Read more
Affected Products : edit_comments- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24472
The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from ... Read more
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24507
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) ... Read more
Affected Products : astra- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24442
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform... Read more
Affected Products : poll\,_survey\,_questionnaire_and_voting_system- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2002-0059
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via... Read more
Affected Products : zlib- Published: Mar. 15, 2002
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2021-24384
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though t... Read more
Affected Products : joomsport- Published: Jul. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24376
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction. However, the extracted folders are not checked and it is possible to upload ... Read more
Affected Products : autoptimize- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24375
Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary files in the ser... Read more
Affected Products : motor- Published: Jul. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24321
The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them i... Read more
Affected Products : bello- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24314
The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue... Read more
Affected Products : goto- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24370
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.... Read more
Affected Products : fancy_product_designer- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024