Latest CVE Feed
-
8.1
HIGHCVE-2021-24197
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user t... Read more
Affected Products : wpdatatables- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24196
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized... Read more
Affected Products : social_slider_widget- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24195
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as we... Read more
Affected Products : login_as_user_or_customer_\(user_switching\)- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24194
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, a... Read more
Affected Products : login_protection_-_limit_failed_login_attempts- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24193
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as... Read more
Affected Products : visitor_traffic_real_time_statistics- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24192
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugi... Read more
Affected Products : sitemap- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24191
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, ... Read more
Affected Products : coming_soon_page_\&_maintenance_mode- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24190
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as we... Read more
Affected Products : conditional_marketing_mailer- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24189
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository... Read more
Affected Products : captchinoo- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24188
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as... Read more
Affected Products : wp_content_copy_protection_\&_no_right_click- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24187
The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.... Read more
Affected Products : seo_redirection- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24186
The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.... Read more
Affected Products : tutor_lms- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24185
The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.... Read more
Affected Products : tutor_lms- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24184
Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.... Read more
Affected Products : tutor_lms- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24183
The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.... Read more
Affected Products : tutor_lms- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24182
The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.... Read more
Affected Products : tutor_lms- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24181
The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.... Read more
Affected Products : tutor_lms- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24180
Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capab... Read more
Affected Products : related_posts- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24179
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate ... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24178
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024