|
197021
|
3.5 |
LOW
Network
|
wpdevart
|
duplicate_page_or_post
|
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any auth…
|
-
|
CVE-2021-25075
|
2024-11-21 14:54 |
2022-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197022
|
8.8 |
HIGH
Network
|
wpdownloadmanager
|
download_manager
|
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited …
|
-
|
CVE-2021-25069
|
2024-11-21 14:54 |
2022-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197023
|
5.4 |
MEDIUM
Network
|
fivestarplugins
|
five_star_business_profile_and_schema
|
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX a…
|
-
|
CVE-2021-25060
|
2024-11-21 14:54 |
2022-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197024
|
5.4 |
MEDIUM
Network
|
the_buffer_button_project
|
the_buffer_button
|
The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within the Twitter username to mention text field.
|
-
|
CVE-2021-25058
|
2024-11-21 14:54 |
2022-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197025
|
5.4 |
MEDIUM
Network
|
translationexchange
|
translation_exchange
|
The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings.
|
-
|
CVE-2021-25057
|
2024-11-21 14:54 |
2022-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197026
|
6.1 |
MEDIUM
Network
|
feedwordpress_project
|
feedwordpress
|
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25055
|
2024-11-21 14:54 |
2022-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197027
|
6.1 |
MEDIUM
Network
|
sigmaplugin
|
advanced_database_cleaner
|
The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting iss…
|
-
|
CVE-2021-24921
|
2024-11-21 14:54 |
2022-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197028
|
6.4 |
MEDIUM
Network
|
wp_photo_album_plus_project
|
wp_photo_album_plus
|
The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could c…
|
-
|
CVE-2021-25115
|
2024-11-21 14:54 |
2022-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197029
|
4.3 |
MEDIUM
Network
|
futuriowp
|
futurio_extra
|
The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address.
|
-
|
CVE-2021-25110
|
2024-11-21 14:54 |
2022-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197030
|
2.7 |
LOW
Network
|
futuriowp
|
futurio_extra
|
The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cr…
|
CWE-89
SQL Injection
|
CVE-2021-25109
|
2024-11-21 14:54 |
2022-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|