|
195161
|
8.8 |
HIGH
Network
|
strategy11
|
business_directory_plugin_-_easy_listing_directories
|
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in adminis…
|
-
|
CVE-2021-24178
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195162
|
6.1 |
MEDIUM
Network
|
imagely
|
nextgen_gallery
|
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is a…
|
-
|
CVE-2021-24293
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195163
|
6.1 |
MEDIUM
Network
|
supsystic
|
contact_form
|
The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting i…
|
-
|
CVE-2021-24276
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195164
|
6.1 |
MEDIUM
Network
|
supsystic
|
popup
|
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
|
-
|
CVE-2021-24275
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195165
|
6.1 |
MEDIUM
Network
|
supsystic
|
ultimate_maps
|
The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting i…
|
-
|
CVE-2021-24274
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195166
|
5.4 |
MEDIUM
Network
|
cleversoft
|
clever_addons_for_elementor
|
The “Clever Addons for Elementor” WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a …
|
-
|
CVE-2021-24273
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195167
|
4.3 |
MEDIUM
Network
|
codeinitiator
|
fitness_calculators
|
The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in u…
|
-
|
CVE-2021-24272
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195168
|
5.4 |
MEDIUM
Network
|
brainstormforce
|
ultimate_addons_for_elementor
|
The “Ultimate Addons for Elementor” WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via…
|
-
|
CVE-2021-24271
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195169
|
5.4 |
MEDIUM
Network
|
detheme
|
dethemekit_for_elementor
|
The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar …
|
-
|
CVE-2021-24270
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195170
|
5.4 |
MEDIUM
Network
|
sinaextra
|
sina_extension_for_elementor
|
The “Sina Extension for Elementor” WordPress Plugin before 3.3.12 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24269
|
2024-11-21 14:52 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|