|
197321
|
5.4 |
MEDIUM
Network
|
insert_pages_project
|
insert_pages
|
The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site…
|
-
|
CVE-2021-24850
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197322
|
8.8 |
HIGH
Network
|
wp-buy
|
seo_redirection-301_redirect_manager
|
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset para…
|
-
|
CVE-2021-24847
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197323
|
4.8 |
MEDIUM
Network
|
helpful_project
|
helpful
|
The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_h…
|
-
|
CVE-2021-24841
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197324
|
5.4 |
MEDIUM
Network
|
yop-poll
|
yop_poll
|
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is all…
|
-
|
CVE-2021-24834
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197325
|
5.4 |
MEDIUM
Network
|
yop-poll
|
yop_poll
|
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to…
|
-
|
CVE-2021-24833
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197326
|
4.8 |
MEDIUM
Network
|
wpplugin
|
accept_donations_with_paypal
|
The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting …
|
-
|
CVE-2021-24815
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197327
|
8.8 |
HIGH
Network
|
simple_jwt_login_project
|
simple_jwt_login
|
The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification s…
|
-
|
CVE-2021-24804
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197328
|
6.5 |
MEDIUM
Network
|
gesundheit-bewegt
|
colorful_categories
|
The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack
|
-
|
CVE-2021-24802
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197329
|
6.1 |
MEDIUM
Network
|
my_tickets_project
|
my_tickets
|
The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenti…
|
-
|
CVE-2021-24796
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197330
|
4.8 |
MEDIUM
Network
|
webventures
|
client_invoicing_by_sprout_invoices
|
The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attack…
|
-
|
CVE-2021-24787
|
2024-11-21 14:53 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|