Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.0

    HIGH
    CVE-2021-24209

    The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp... Read more

    Affected Products : wp_super_cache
    • EPSS Score: %1.62
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-24208

    The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML, including JavaScript, into pages via the “Raw HTML” widget and the “Custom HTML” widgets (though the custom HTML widget requires sendi... Read more

    Affected Products : wp_page_builder
    • EPSS Score: %0.42
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2021-24207

    By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.... Read more

    Affected Products : wp_page_builder
    • EPSS Score: %0.17
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-24206

    In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Co... Read more

    Affected Products : website_builder
    • EPSS Score: %0.10
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-24205

    In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Cont... Read more

    Affected Products : website_builder
    • EPSS Score: %0.10
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-24204

    In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user wit... Read more

    Affected Products : website_builder
    • EPSS Score: %0.10
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-24203

    In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contrib... Read more

    Affected Products : website_builder
    • EPSS Score: %0.10
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-24202

    In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contr... Read more

    Affected Products : website_builder
    • EPSS Score: %0.10
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-24201

    In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contrib... Read more

    Affected Products : website_builder
    • EPSS Score: %0.11
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-24200

    The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_... Read more

    Affected Products : wpdatatables
    • EPSS Score: %0.90
    • Published: Apr. 12, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-24199

    The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_... Read more

    Affected Products : wpdatatables
    • EPSS Score: %0.90
    • Published: Apr. 12, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-24198

    The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to delete the data of another user t... Read more

    Affected Products : wpdatatables
    • EPSS Score: %0.64
    • Published: Apr. 12, 2021
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2021-24197

    The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user t... Read more

    Affected Products : wpdatatables
    • EPSS Score: %0.38
    • Published: Apr. 12, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2021-24196

    The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized... Read more

    Affected Products : social_slider_widget
    • EPSS Score: %0.20
    • Published: Apr. 05, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-24195

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as we... Read more

    • EPSS Score: %0.60
    • Published: May. 14, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-24194

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, a... Read more

    • EPSS Score: %0.60
    • Published: May. 14, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-24193

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as... Read more

    • EPSS Score: %0.60
    • Published: May. 14, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-24192

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugi... Read more

    Affected Products : sitemap
    • EPSS Score: %0.60
    • Published: May. 14, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-24191

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, ... Read more

    • EPSS Score: %0.60
    • Published: May. 14, 2021
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-24190

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as we... Read more

    Affected Products : conditional_marketing_mailer
    • EPSS Score: %0.60
    • Published: May. 14, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 290974 Results