Latest CVE Feed
-
6.1
MEDIUMCVE-2021-24921
The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues... Read more
Affected Products : advanced_database_cleaner- EPSS Score: %0.21
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24920
The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : statcounter- EPSS Score: %0.21
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24919
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection... Read more
Affected Products : wicked_folders- EPSS Score: %0.65
- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24918
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript o... Read more
Affected Products : smash_balloon_social_post_feed- EPSS Score: %0.18
- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-24917
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.... Read more
Affected Products : wps_hide_login- EPSS Score: %76.40
- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-24916
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.... Read more
Affected Products : qubely- EPSS Score: %3.35
- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24915
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unaut... Read more
Affected Products : contest_gallery- EPSS Score: %74.56
- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-24914
The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-privileged users (including simple sub... Read more
Affected Products : tawk.to_live_chat- EPSS Score: %0.10
- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-24913
The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_data AJAX action, allowing attackers to make a logged in high privilege user, change title, description, alt text, and URL of arbitrary... Read more
Affected Products : logo_showcase_with_slick_slider- EPSS Score: %0.10
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24912
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this... Read more
Affected Products : transposh_wordpress_translation- EPSS Score: %0.20
- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24911
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The mini... Read more
Affected Products : transposh_wordpress_translation- EPSS Score: %0.48
- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24910
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in t... Read more
Affected Products : transposh_wordpress_translation- EPSS Score: %11.94
- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24909
The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issue... Read more
Affected Products : acf_photo_gallery_field- EPSS Score: %0.29
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24908
The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : check_\&_log_email- EPSS Score: %0.21
- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24907
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue... Read more
Affected Products : everest_forms- EPSS Score: %0.47
- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-24906
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request... Read more
Affected Products : protect_wp_admin- EPSS Score: %1.45
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-24905
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary fil... Read more
Affected Products : advanced_cf7_db- EPSS Score: %0.13
- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24904
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfilt... Read more
Affected Products : mortgage_calculators_wp- EPSS Score: %3.04
- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24903
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : grand_flagallery- EPSS Score: %0.21
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24902
The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability i... Read more
Affected Products : typebot- EPSS Score: %0.21
- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024