|
195211
|
8.8 |
HIGH
Network
|
expresstech
|
quiz_and_survey_master
|
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attr…
|
-
|
CVE-2021-24221
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195212
|
9.1 |
CRITICAL
Network
|
thrivethemes
|
ignition luxe minus performag pressive rise squared storied voice focusblog
|
Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes …
|
-
|
CVE-2021-24220
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195213
|
5.3 |
MEDIUM
Network
|
thrivethemes
|
thrive_ovation thrive_dashboard thrive_visual_editor thrive_apprentice thrive_quiz_builder thrive_headline_optimizer thrive_comments thrive_optimize thrive_clever_widgets f…
|
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-24219
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195214
|
8.1 |
HIGH
Network
|
facebook
|
facebook
|
The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it possible for PHP objects to be supplied creating an Object Injection vulnerability.…
|
-
|
CVE-2021-24217
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195215
|
9.8 |
CRITICAL
Network
|
wpruby
|
controlled_admin_access
|
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS set…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2021-24215
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195216
|
6.1 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET…
|
-
|
CVE-2021-24213
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195217
|
6.5 |
MEDIUM
Network
|
tms-outsource
|
wpdatatables
|
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the end…
|
-
|
CVE-2021-24200
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195218
|
6.5 |
MEDIUM
Network
|
tms-outsource
|
wpdatatables
|
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the end…
|
-
|
CVE-2021-24199
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195219
|
8.1 |
HIGH
Network
|
tms-outsource
|
wpdatatables
|
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can ta…
|
NVD-CWE-Other
|
CVE-2021-24198
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195220
|
8.1 |
HIGH
Network
|
tms-outsource
|
wpdatatables
|
The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can ta…
|
NVD-CWE-Other
|
CVE-2021-24197
|
2024-11-21 14:52 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|