Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24912
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this... Read more
Affected Products : transposh_wordpress_translation- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24911
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from the tp_translation AJAX action, leading to Stored Cross-Site Scripting, which will trigger in the admin dashboard of the plugin. The mini... Read more
Affected Products : transposh_wordpress_translation- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24910
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in t... Read more
Affected Products : transposh_wordpress_translation- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24909
The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issue... Read more
Affected Products : acf_photo_gallery_field- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24908
The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : check_\&_log_email- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24907
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue... Read more
Affected Products : everest_forms- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-24906
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request... Read more
Affected Products : protect_wp_admin- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-24905
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary fil... Read more
Affected Products : advanced_cf7_db- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24904
The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfilt... Read more
Affected Products : mortgage_calculators_wp- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24903
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : grand_flagallery- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24902
The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability i... Read more
Affected Products : typebot- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24901
The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.... Read more
Affected Products : security_audit- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24900
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : ninja_tables- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24899
The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed.... Read more
Affected Products : media-tags- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24898
The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : editable_table- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24897
The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with classic editor) when output in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks... Read more
Affected Products : add_subtitle- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24896
The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more
Affected Products : caldera_forms- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24895
The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is d... Read more
Affected Products : cybersoldier- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24894
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be disp... Read more
Affected Products : reviews_plus- Published: Nov. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-24893
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated ... Read more
Affected Products : stars_rating- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024