Latest CVE Feed
-
7.5
HIGHCVE-2021-24146
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.... Read more
Affected Products : modern_events_calendar_lite- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-24145
Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.... Read more
Affected Products : modern_events_calendar_lite- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-24144
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.... Read more
Affected Products : contact_form_7_database_addon- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24143
Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.... Read more
Affected Products : accesspress_social_icons- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-24142
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.... Read more
Affected Products : 301_redirects- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-24141
Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks.... Read more
Affected Products : advanced_database_cleaner- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-24140
Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.... Read more
Affected Products : ajax_load_more- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24139
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.... Read more
Affected Products : photo_gallery- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-24138
Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.... Read more
Affected Products : adrotate- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24137
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.... Read more
Affected Products : blog2social- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24136
Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below pa... Read more
Affected Products : testimonials_widget- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-24135
Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.... Read more
Affected Products : wp_customer_reviews- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-24134
Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript ... Read more
Affected Products : constant_contact_forms- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-24133
Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account.... Read more
Affected Products : activecampaign- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-24132
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" ... Read more
Affected Products : slider- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-24131
Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).... Read more
Affected Products : anti-spam- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24129
Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Scripting (XSS) vulnerabilities allowing low-privileged users (Contributor+) to inject arbitrary JavaScript code... Read more
Affected Products : portfolio_post- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24128
Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML... Read more
Affected Products : team_members- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24127
Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.... Read more
Affected Products : thirstyaffiliates_affiliate_link_manager- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24126
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege... Read more
Affected Products : envira_gallery- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024