Latest CVE Feed
-
8.8
HIGHCVE-2021-25030
The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low a... Read more
Affected Products : events_made_easy- EPSS Score: %0.71
- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-25029
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : learning_management_system- EPSS Score: %0.21
- Published: Feb. 07, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25028
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue... Read more
Affected Products : event_tickets- EPSS Score: %4.40
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25027
The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue... Read more
Affected Products : powerpack_addons_for_elementor- EPSS Score: %0.21
- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-25026
The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : patreon_wordpress- EPSS Score: %0.18
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-25025
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events... Read more
Affected Products : eventcalendar- EPSS Score: %0.10
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25024
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues... Read more
Affected Products : eventcalendar- EPSS Score: %0.21
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-25023
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_table_name parameter before using it in a SQL statement to convert the related table, leading to an SQL injection... Read more
Affected Products : speed_booster_pack- EPSS Score: %0.53
- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-25021
The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin... Read more
Affected Products : optimize_my_google_fonts- EPSS Score: %0.42
- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-25020
The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin... Read more
Affected Products : complete_analytics_optimization_suite- EPSS Score: %0.48
- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25019
The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : seo_plugin_by_squirrly_seo- EPSS Score: %0.27
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25018
The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_panel_action AJAX action, allowing any authenticated to call it and set arbitrary settings. Furthermore, due to the lack of sanitisation... Read more
Affected Products : ppom_for_woocommerce- EPSS Score: %0.13
- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25017
The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : tutor_lms- EPSS Score: %0.29
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25016
The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting... Read more
- EPSS Score: %10.38
- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25015
The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue... Read more
Affected Products : mycred- EPSS Score: %0.21
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-25014
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Store... Read more
Affected Products : ibtana- EPSS Score: %0.14
- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-25013
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscrib... Read more
Affected Products : qubely- EPSS Score: %0.14
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25012
The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues... Read more
Affected Products : pz-linkcard- EPSS Score: %0.20
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-25011
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's se... Read more
Affected Products : wp_google_map- EPSS Score: %0.10
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-25010
The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored ... Read more
Affected Products : post_snippets- EPSS Score: %0.15
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024