Latest CVE Feed
-
6.1
MEDIUMCVE-2021-24297
The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.... Read more
Affected Products : goto- EPSS Score: %0.26
- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24296
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled... Read more
Affected Products : wp_customer_reviews- EPSS Score: %0.19
- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-24295
It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included ... Read more
Affected Products : spam_protection\,_antispam\,_firewall- EPSS Score: %0.95
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24294
The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiof... Read more
- EPSS Score: %7.19
- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24293
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.... Read more
Affected Products : nextgen_gallery- EPSS Score: %0.39
- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24292
The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, a... Read more
Affected Products : happy_addons_for_elementor- EPSS Score: %0.22
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24291
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (a... Read more
Affected Products : photo_gallery- EPSS Score: %14.62
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24290
There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.... Read more
Affected Products : store_locator_plus- EPSS Score: %2.97
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24289
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.... Read more
Affected Products : store_locator_plus- EPSS Score: %0.75
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24288
When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.... Read more
Affected Products : acymailing- EPSS Score: %4.40
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24287
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue... Read more
Affected Products : select_all_categories_and_taxonomies\,_change_checkbox_to_radio_buttons- EPSS Score: %18.58
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24286
The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue... Read more
Affected Products : redirect_404_to_parent- EPSS Score: %34.43
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24285
The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in ... Read more
Affected Products : cars-seller-auto-classifieds-script- EPSS Score: %85.67
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24284
The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for ma... Read more
Affected Products : kaswara- EPSS Score: %91.33
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24283
The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, leading to a reflected XSS issue.... Read more
Affected Products : accordion- EPSS Score: %0.18
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24282
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to rese... Read more
Affected Products : redirection_for_contact_form_7- EPSS Score: %0.25
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-24281
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.... Read more
Affected Products : redirection_for_contact_form_7- EPSS Score: %0.16
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24280
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.... Read more
Affected Products : redirection_for_contact_form_7- EPSS Score: %3.38
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24279
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.... Read more
Affected Products : redirection_for_contact_form_7- EPSS Score: %0.26
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-24278
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.... Read more
Affected Products : redirection_for_contact_form_7- EPSS Score: %35.22
- Published: May. 14, 2021
- Modified: Nov. 21, 2024