|
196171
|
5.4 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link t…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24306
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196172
|
6.1 |
MEDIUM
Network
|
targetfirst
|
watcheezy
|
The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a …
|
-
|
CVE-2021-24305
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196173
|
5.4 |
MEDIUM
Network
|
neox
|
hana_flv_player
|
The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.
|
-
|
CVE-2021-24302
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196174
|
5.4 |
MEDIUM
Network
|
bluemedicinelabs
|
hotjar_connecticator
|
The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly veri…
|
-
|
CVE-2021-24301
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196175
|
6.1 |
MEDIUM
Network
|
pickplugins
|
product_slider_for_woocommerce
|
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Sit…
|
-
|
CVE-2021-24300
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196176
|
6.1 |
MEDIUM
Network
|
ibenic
|
simple_giveaways
|
The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS
|
-
|
CVE-2021-24298
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196177
|
6.1 |
MEDIUM
Network
|
boostifythemes
|
goto
|
The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulner…
|
-
|
CVE-2021-24297
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196178
|
4.8 |
MEDIUM
Network
|
gowebsolutions
|
wp_customer_reviews
|
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be trigge…
|
-
|
CVE-2021-24296
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196179
|
6.1 |
MEDIUM
Network
|
mlfactory
|
dsgvo_all_in_one_for_wp
|
The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the ad…
|
-
|
CVE-2021-24294
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196180
|
4.8 |
MEDIUM
Network
|
clogica
|
seo_redirection_plugin
|
The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high pr…
|
-
|
CVE-2021-24327
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|