Latest CVE Feed
-
6.5
MEDIUMCVE-2021-25072
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack... Read more
Affected Products : social_networks_auto_poster- EPSS Score: %0.10
- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25071
The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : akismet_privacy_policies- EPSS Score: %0.20
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25070
The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue... Read more
- EPSS Score: %0.52
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-25068
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard... Read more
Affected Products : sync_woocommerce_product_feed_to_google_shopping- EPSS Score: %0.54
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25067
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.... Read more
Affected Products : landing_page- EPSS Score: %4.86
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-25066
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : ninja_forms- EPSS Score: %0.27
- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25065
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.... Read more
Affected Products : smash_balloon_social_post_feed- EPSS Score: %2.93
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-25064
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.... Read more
Affected Products : wow_countdowns- EPSS Score: %0.79
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25063
The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : contact_form_7_skins- EPSS Score: %1.16
- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25062
The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : orders_tracking_for_woocommerce- EPSS Score: %0.21
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25061
The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.... Read more
Affected Products : wp_booking_system- EPSS Score: %1.26
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25060
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscri... Read more
Affected Products : five_star_business_profile_and_schema- EPSS Score: %0.21
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25058
The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within the Twitter username to mention text field.... Read more
Affected Products : the_buffer_button- EPSS Score: %0.21
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25057
The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings.... Read more
Affected Products : translation_exchange- EPSS Score: %0.21
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-25056
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : ninja_forms- EPSS Score: %0.20
- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25055
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.... Read more
Affected Products : feedwordpress- EPSS Score: %1.04
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25054
The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.... Read more
Affected Products : wpcalc- EPSS Score: %0.66
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25053
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.... Read more
Affected Products : wp_coder- EPSS Score: %0.11
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25052
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.... Read more
Affected Products : button_generator- EPSS Score: %26.37
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25051
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.... Read more
Affected Products : modal_window- EPSS Score: %0.10
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024