Latest CVE Feed
-
9.0
HIGHCVE-2021-24209
The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp... Read more
Affected Products : wp_super_cache- EPSS Score: %1.62
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24208
The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML, including JavaScript, into pages via the “Raw HTML” widget and the “Custom HTML” widgets (though the custom HTML widget requires sendi... Read more
Affected Products : wp_page_builder- EPSS Score: %0.42
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-24207
By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.... Read more
Affected Products : wp_page_builder- EPSS Score: %0.17
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24206
In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Co... Read more
Affected Products : website_builder- EPSS Score: %0.10
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24205
In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Cont... Read more
Affected Products : website_builder- EPSS Score: %0.10
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24204
In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user wit... Read more
Affected Products : website_builder- EPSS Score: %0.10
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24203
In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contrib... Read more
Affected Products : website_builder- EPSS Score: %0.10
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24202
In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contr... Read more
Affected Products : website_builder- EPSS Score: %0.10
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24201
In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contrib... Read more
Affected Products : website_builder- EPSS Score: %0.11
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24200
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_... Read more
Affected Products : wpdatatables- EPSS Score: %0.90
- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24199
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_... Read more
Affected Products : wpdatatables- EPSS Score: %0.90
- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-24198
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to delete the data of another user t... Read more
Affected Products : wpdatatables- EPSS Score: %0.64
- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-24197
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user t... Read more
Affected Products : wpdatatables- EPSS Score: %0.38
- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24196
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized... Read more
Affected Products : social_slider_widget- EPSS Score: %0.20
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24195
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as we... Read more
Affected Products : login_as_user_or_customer_\(user_switching\)- EPSS Score: %0.60
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24194
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, a... Read more
Affected Products : login_protection_-_limit_failed_login_attempts- EPSS Score: %0.60
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24193
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as... Read more
Affected Products : visitor_traffic_real_time_statistics- EPSS Score: %0.60
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24192
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugi... Read more
Affected Products : sitemap- EPSS Score: %0.60
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24191
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, ... Read more
Affected Products : coming_soon_page_\&_maintenance_mode- EPSS Score: %0.60
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24190
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as we... Read more
Affected Products : conditional_marketing_mailer- EPSS Score: %0.60
- Published: May. 14, 2021
- Modified: Nov. 21, 2024