|
196091
|
8.8 |
HIGH
Network
|
cozmoslabs
|
membership_\&_content_restriction_-_paid_member_subscriptions
|
The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement…
|
-
|
CVE-2021-24728
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196092
|
8.8 |
HIGH
Network
|
stopbadbots
|
block_and_stop_bad_bots
|
The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections
|
-
|
CVE-2021-24727
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196093
|
8.8 |
HIGH
Network
|
wpsimplebookingcalendar
|
wp_simple_booking_calendar
|
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to …
|
-
|
CVE-2021-24726
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196094
|
4.3 |
MEDIUM
Network
|
quantumcloud
|
comment_link_remove_and_other_comment_tools
|
The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbi…
|
-
|
CVE-2021-24725
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196095
|
5.4 |
MEDIUM
Network
|
motopress
|
timetable_and_event_schedule
|
The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks agai…
|
-
|
CVE-2021-24724
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196096
|
4.8 |
MEDIUM
Network
|
ticket-system
|
wordpress_advanced_ticket_system
|
The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape form values before saving to the database or when outputting, which allows high…
|
-
|
CVE-2021-24623
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196097
|
4.8 |
MEDIUM
Network
|
stratospheredigital
|
wp_courses_lms
|
The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capabilit…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24621
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196098
|
8.8 |
HIGH
Network
|
simple-e-commerce-shopping-cart_project
|
simple-e-commerce-shopping-cart
|
The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PH…
|
CWE-352 CWE-434
Origin Validation Error Unrestricted Upload of File with Dangerous Type
|
CVE-2021-24620
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196099
|
4.8 |
MEDIUM
Network
|
evona
|
per_page_add_to_head
|
The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html cap…
|
-
|
CVE-2021-24619
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196100
|
4.8 |
MEDIUM
Network
|
oz-plugin
|
book_appointment_online
|
The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scri…
|
-
|
CVE-2021-24614
|
2024-11-21 14:53 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|