Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24247
The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin setti... Read more
Affected Products : contact_form_check_tester- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24246
The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24245
The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-... Read more
Affected Products : stop_spammers- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24244
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).... Read more
Affected Products : wpbakery_page_builder_clipboard- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24243
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be tri... Read more
Affected Products : wpbakery_page_builder_clipboard- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-24242
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowing high privilege users to include a... Read more
Affected Products : tutor_lms- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24241
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings page.... Read more
Affected Products : advanced_custom_fields- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24240
The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability.... Read more
Affected Products : business_hours_pro- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24239
The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cr... Read more
Affected Products : pie_register- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24238
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any authenticated users to delete arbitrary properties by tampering with the prop... Read more
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24237
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page, leading to an unauthenticated reflecte... Read more
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24236
The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid ima... Read more
Affected Products : imagements- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24235
The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.... Read more
Affected Products : goto- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24234
The Search Forms page of the Ivory Search WordPress lugin before 4.6.1 did not properly sanitise the tab parameter before output it in the page, leading to a reflected Cross-Site Scripting issue when opening a malicious crafted link as a high privilege us... Read more
Affected Products : ivory_search- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24233
The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output back in pages as an arbitrary attribute.... Read more
Affected Products : cooked- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24232
The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue... Read more
Affected Products : advanced_booking_calendar- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-24231
The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconnect the site from Patreon by visiting a specially crafted link.... Read more
Affected Products : patreon_wordpress- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-24230
The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user metadata on the victim’s account once visited. If expl... Read more
Affected Products : patreon_wordpress- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-24229
The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to ... Read more
Affected Products : patreon_wordpress- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-24228
The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and offers to allow users to authenticate on the site using t... Read more
Affected Products : patreon_wordpress- Published: Apr. 12, 2021
- Modified: Nov. 21, 2024