|
196021
|
5.4 |
MEDIUM
Network
|
bplugins
|
streamcast_radio_player
|
The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scr…
|
-
|
CVE-2021-24416
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196022
|
5.4 |
MEDIUM
Network
|
bplugins
|
polo_video_gallery
|
The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contrib…
|
-
|
CVE-2021-24415
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196023
|
5.4 |
MEDIUM
Network
|
bplugins
|
easy_twitter_feed
|
The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload…
|
-
|
CVE-2021-24413
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196024
|
5.4 |
MEDIUM
Network
|
bplugins
|
html5_audio_player
|
The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-…
|
-
|
CVE-2021-24412
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196025
|
5.7 |
MEDIUM
Network
|
catchplugins
|
catch_scroll_progress_bar catch_sticky_menu catch_themes_demo_import catch_under_construction catch_web_tools essential_content_types generate_child_theme header_enhancement t…
|
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essen…
|
CWE-352
Origin Validation Error
|
CVE-2021-24752
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196026
|
4.8 |
MEDIUM
Network
|
gvectors
|
wpdiscuz
|
The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users…
|
-
|
CVE-2021-24737
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196027
|
5.4 |
MEDIUM
Network
|
ayecode
|
geodirectory
|
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
|
-
|
CVE-2021-24720
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196028
|
6.1 |
MEDIUM
Network
|
kriesi
|
enfold
|
The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.
|
CWE-79
Cross-site Scripting
|
CVE-2021-24719
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196029
|
5.4 |
MEDIUM
Network
|
dwbooster
|
appointment_hour_booking
|
The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.
|
CWE-79
Cross-site Scripting
|
CVE-2021-24712
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196030
|
8.8 |
HIGH
Network
|
tipsandtricks-hq
|
software_license_manager
|
The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack
|
-
|
CVE-2021-24711
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|