|
195941
|
7.2 |
HIGH
Network
|
timeline_calendar_project
|
timeline_calendar
|
The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL…
|
-
|
CVE-2021-24553
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195942
|
7.2 |
HIGH
Network
|
simple_events_calendar_project
|
simple_events_calendar
|
The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an auth…
|
-
|
CVE-2021-24552
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195943
|
9.8 |
CRITICAL
Network
|
edit_comments_project
|
edit_comments
|
The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue
|
-
|
CVE-2021-24551
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195944
|
7.2 |
HIGH
Network
|
broken_link_manager_project
|
broken_link_manager
|
The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an aut…
|
-
|
CVE-2021-24550
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195945
|
4.9 |
MEDIUM
Network
|
aceide_project
|
aceide
|
The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths before using it in various actions, such as to read arbitrary files from the s…
|
-
|
CVE-2021-24549
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195946
|
5.4 |
MEDIUM
Network
|
kn_fix_your_title_project
|
kn_fix_your_title
|
The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field.
|
-
|
CVE-2021-24547
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195947
|
4.8 |
MEDIUM
Network
|
webfactoryltd
|
maintenance
|
The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the un…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24533
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195948
|
5.4 |
MEDIUM
Network
|
wpcharitable
|
charitable
|
The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site scripting vulnerability which was found in the add donation feature.
|
-
|
CVE-2021-24531
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195949
|
5.4 |
MEDIUM
Network
|
awplife
|
grid_gallery
|
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an auth…
|
-
|
CVE-2021-24529
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195950
|
4.8 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site S…
|
-
|
CVE-2021-24524
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|