|
195821
|
5.7 |
MEDIUM
Network
|
catchplugins
|
catch_scroll_progress_bar catch_sticky_menu catch_themes_demo_import catch_under_construction catch_web_tools essential_content_types generate_child_theme header_enhancement t…
|
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essen…
|
CWE-352
Origin Validation Error
|
CVE-2021-24752
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195822
|
4.8 |
MEDIUM
Network
|
gvectors
|
wpdiscuz
|
The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users…
|
-
|
CVE-2021-24737
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195823
|
5.4 |
MEDIUM
Network
|
ayecode
|
geodirectory
|
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
|
-
|
CVE-2021-24720
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195824
|
6.1 |
MEDIUM
Network
|
kriesi
|
enfold
|
The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.
|
CWE-79
Cross-site Scripting
|
CVE-2021-24719
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195825
|
5.4 |
MEDIUM
Network
|
dwbooster
|
appointment_hour_booking
|
The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.
|
CWE-79
Cross-site Scripting
|
CVE-2021-24712
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195826
|
8.8 |
HIGH
Network
|
tipsandtricks-hq
|
software_license_manager
|
The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack
|
-
|
CVE-2021-24711
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195827
|
4.8 |
MEDIUM
Network
|
awplife
|
weather_effect
|
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting …
|
-
|
CVE-2021-24709
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195828
|
4.8 |
MEDIUM
Network
|
expresstech
|
quiz_and_survey_master
|
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scr…
|
-
|
CVE-2021-24691
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195829
|
5.4 |
MEDIUM
Network
|
kibokolabs
|
chained_quiz
|
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
|
-
|
CVE-2021-24690
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195830
|
5.4 |
MEDIUM
Network
|
awplife
|
weather_effect
|
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting i…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2021-24683
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|