|
197961
|
6.5 |
MEDIUM
Network
|
improved_include_page_project
|
improved_include_page
|
The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as…
|
NVD-CWE-Other
|
CVE-2021-24845
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197962
|
4.3 |
MEDIUM
Network
|
storeapps
|
temporary_login_without_password
|
The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers …
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2021-24836
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197963
|
4.3 |
MEDIUM
Network
|
page\/post_content_shortcode_project
|
page\/post_content_shortcode
|
The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/t…
|
CWE-863
Incorrect Authorization
|
CVE-2021-24819
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197964
|
4.3 |
MEDIUM
Network
|
wp_limits_project
|
wp_limits
|
The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make a logged in admin change them, which could make the blog unstable by setting lo…
|
-
|
CVE-2021-24818
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197965
|
5.4 |
MEDIUM
Network
|
ultimate_nofollow_project
|
ultimate_nofollow
|
The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scriptin…
|
-
|
CVE-2021-24817
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197966
|
6.5 |
MEDIUM
Network
|
phoeniixx
|
filter_portfolio_gallery
|
The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbi…
|
-
|
CVE-2021-24795
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197967
|
6.1 |
MEDIUM
Network
|
wpeden
|
shiny_buttons
|
The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and es…
|
-
|
CVE-2021-24792
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197968
|
4.3 |
MEDIUM
Network
|
contact_form_advanced_database_project
|
contact_form_advanced_database
|
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any auth…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2021-24790
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197969
|
6.5 |
MEDIUM
Network
|
wp_admin_logo_changer_project
|
wp_admin_logo_changer
|
The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.
|
-
|
CVE-2021-24784
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197970
|
4.8 |
MEDIUM
Network
|
flex_local_fonts_project
|
flex_local_fonts
|
The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when …
|
-
|
CVE-2021-24782
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|