Latest CVE Feed
-
6.1
MEDIUMCVE-2021-38343
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.... Read more
Affected Products : nested_pages- EPSS Score: %0.19
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-38342
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status,... Read more
Affected Products : nested_pages- EPSS Score: %0.10
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38341
The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php file which allows attackers to inject arbitrary web scripts, ... Read more
Affected Products : woocommerce_payment_gateway_per_category- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38340
The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.... Read more
Affected Products : wordpress_simple_shop- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38339
The Simple Matted Thumbnails WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/simple-matted-thumbnail.php file which allows attackers to inject arbitrary web scripts, in versions up to... Read more
Affected Products : simple_matted_thumbnails- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38338
The Border Loading Bar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `f` and `t` parameter found in the ~/titan-framework/iframe-googlefont-preview.php file which allows attackers to inject arbitrary web scripts, in versions up ... Read more
Affected Products : border_loading_bar- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38337
The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php file which allows attackers to inject arbitrary web scripts, in ver... Read more
Affected Products : rsvpmaker_excel- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38336
The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/edit-comments-xt.php file which allows attackers to inject arbitrary web scripts, in versions up to and including ... Read more
Affected Products : edit_comments_xt- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38335
The Wise Agent Capture Forms WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/WiseAgentCaptureForm.php file which allows attackers to inject arbitrary web scripts, in versions up to an... Read more
Affected Products : wise_agent_capture_forms- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38334
The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter found in the ~/wpdmp-admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.... Read more
Affected Products : wp-design-maps-places- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38333
The WP Scrippets WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/wp-scrippets.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.1.... Read more
Affected Products : wp_scrippets- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38332
The On Page SEO + Whatsapp Chat Button Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/settings.php file which allows attackers to inject arbitrary web scripts, in versions up ... Read more
Affected Products : ops-robots-txt- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38331
The WP-T-Wap WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the posted parameter found in the ~/wap/writer.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.13.2.... Read more
Affected Products : wp-t-wap- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38330
The Yet Another bol.com Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/yabp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.... Read more
Affected Products : yabp- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38329
The DJ EmailPublish WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/dj-email-publish.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1... Read more
Affected Products : dj_emailpublish- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38328
The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/notices.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1.... Read more
Affected Products : notices- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38327
The YouTube Video Inserter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/adminUI/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and incl... Read more
Affected Products : youtube_video_inserter- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38326
The Post Title Counter WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the notice parameter found in the ~/post-title-counter.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.... Read more
Affected Products : post_title_counter- EPSS Score: %0.21
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38325
The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter found in the ~/user-activation-email.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.... Read more
Affected Products : user-activation-email- EPSS Score: %0.21
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-38324
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.... Read more
Affected Products : sp_rental_manager- EPSS Score: %0.51
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024