Latest CVE Feed
-
5.4
MEDIUMCVE-2021-25067
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.... Read more
Affected Products : landing_page- EPSS Score: %4.86
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-25066
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : ninja_forms- EPSS Score: %0.27
- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25065
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.... Read more
Affected Products : smash_balloon_social_post_feed- EPSS Score: %2.93
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-25064
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.... Read more
Affected Products : wow_countdowns- EPSS Score: %0.79
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25063
The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : contact_form_7_skins- EPSS Score: %1.16
- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25062
The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : orders_tracking_for_woocommerce- EPSS Score: %0.21
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25061
The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.... Read more
Affected Products : wp_booking_system- EPSS Score: %1.26
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25060
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscri... Read more
Affected Products : five_star_business_profile_and_schema- EPSS Score: %0.21
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25058
The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within the Twitter username to mention text field.... Read more
Affected Products : the_buffer_button- EPSS Score: %0.21
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25057
The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings.... Read more
Affected Products : translation_exchange- EPSS Score: %0.21
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-25056
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : ninja_forms- EPSS Score: %0.20
- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25055
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.... Read more
Affected Products : feedwordpress- EPSS Score: %1.04
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25054
The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.... Read more
Affected Products : wpcalc- EPSS Score: %0.66
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25053
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.... Read more
Affected Products : wp_coder- EPSS Score: %0.11
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25052
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.... Read more
Affected Products : button_generator- EPSS Score: %26.37
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25051
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.... Read more
Affected Products : modal_window- EPSS Score: %0.10
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-25050
The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.... Read more
Affected Products : remove_footer_credit- EPSS Score: %0.21
- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-25049
The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : mobile_events_manager- EPSS Score: %0.31
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25048
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them... Read more
Affected Products : kingcomposer- EPSS Score: %0.44
- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25047
The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users... Read more
Affected Products : 10websocial- EPSS Score: %0.21
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024