Latest CVE Feed
-
5.5
MEDIUMCVE-2021-39338
The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/classes/MyBBXPSettings.php file which allowed attackers with administrative use... Read more
Affected Products : mybb_cross-poster- EPSS Score: %0.41
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39337
The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin/jobs_function.php file which allowed attackers with administrative user access t... Read more
Affected Products : job-portal- EPSS Score: %0.41
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39336
The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with administrative user access to inject... Read more
Affected Products : job_manager- EPSS Score: %0.45
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39335
The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/admin/class/class-wpgenious-job-listing-options.php file which allowed a... Read more
Affected Products : wpgenius_job_listing- EPSS Score: %0.41
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39334
The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the psjb_exp_in and the psjb_curr_in parameters found in the ~/job-settings.php file which allowed attackers with ... Read more
Affected Products : job_board_vanila- EPSS Score: %0.45
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-39333
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables ... Read more
Affected Products : hashthemes_demo_importer- EPSS Score: %0.29
- Published: Nov. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39332
The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization found throughout the plugin which allowed attackers with administrative user access to inject arbitrary web scripts, i... Read more
Affected Products : business_manager- EPSS Score: %0.29
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39329
The JobBoardWP WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-metabox.php file which allowed attackers with administrative user... Read more
Affected Products : jobboardwp- EPSS Score: %0.67
- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39328
The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-settings-privacy.php file which allo... Read more
Affected Products : simple_job_board- EPSS Score: %0.45
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-39327
The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of data... Read more
Affected Products : bulletproof_security- EPSS Score: %90.90
- Published: Sep. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39325
The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php file which allows attackers to inject arbitrary web scripts, in versions u... Read more
Affected Products : optinmonster- EPSS Score: %0.19
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39322
The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack ... Read more
Affected Products : easy_social_icons- EPSS Score: %9.20
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39321
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/... Read more
Affected Products : sassy_social_share- EPSS Score: %1.15
- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39320
The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scriptin... Read more
Affected Products : underconstruction- EPSS Score: %12.01
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39319
The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and inc... Read more
Affected Products : duofaq-responsive-flat-simple-faq- EPSS Score: %0.21
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39318
The H5P CSS Editor WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the h5p-css-file parameter found in the ~/h5p-css-editor.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.... Read more
Affected Products : h5p-css-editor- EPSS Score: %0.21
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39317
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found... Read more
Affected Products : access_demo_importer accesspress-lite accesspress-mag accesspress-parallax accesspress-root accesspress-store accesspress_basic agency-lite arrival bingle +33 more products- EPSS Score: %0.64
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39316
The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.... Read more
Affected Products : zoomsounds- EPSS Score: %89.98
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39315
The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the ~/inc/admin/main.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.... Read more
Affected Products : magic-post-voice- EPSS Score: %0.21
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39314
The WooCommerce EnvioPack WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the dataid parameter found in the ~/includes/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.... Read more
Affected Products : woo-enviopack- EPSS Score: %0.21
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024