|
195441
|
4.8 |
MEDIUM
Network
|
buttonizer
|
buttonizer
|
The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to …
|
-
|
CVE-2021-24992
|
2024-11-21 14:54 |
2021-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195442
|
5.4 |
MEDIUM
Network
|
wprssaggregator
|
wp_rss_aggregator
|
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2021-24988
|
2024-11-21 14:54 |
2021-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195443
|
6.1 |
MEDIUM
Network
|
wpfront
|
wpfront_user_role_editor
|
The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cros…
|
-
|
CVE-2021-24984
|
2024-11-21 14:54 |
2021-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195444
|
6.1 |
MEDIUM
Network
|
gwolle_guestbook_project
|
gwolle_guestbook
|
The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripti…
|
-
|
CVE-2021-24980
|
2024-11-21 14:54 |
2021-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195445
|
6.1 |
MEDIUM
Network
|
strangerstudios
|
paid_memberships_pro
|
The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
|
-
|
CVE-2021-24979
|
2024-11-21 14:54 |
2021-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195446
|
5.4 |
MEDIUM
Network
|
wpdownloadmanager
|
wordpress_download_manager
|
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack …
|
-
|
CVE-2021-24969
|
2024-11-21 14:54 |
2021-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195447
|
6.1 |
MEDIUM
Network
|
themehunk
|
contact_form_\&_lead_form_elementor_builder
|
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting att…
|
-
|
CVE-2021-24967
|
2024-11-21 14:54 |
2021-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195448
|
7.5 |
HIGH
Network
|
wpwax
|
directorist
|
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
|
-
|
CVE-2021-24981
|
2024-11-21 14:54 |
2021-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195449
|
6.1 |
MEDIUM
Network
|
adenion
|
blog2social
|
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Ref…
|
-
|
CVE-2021-24956
|
2024-11-21 14:54 |
2021-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195450
|
6.1 |
MEDIUM
Network
|
icegram
|
icegram
|
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputt…
|
-
|
CVE-2021-24941
|
2024-11-21 14:54 |
2021-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|