|
196011
|
5.4 |
MEDIUM
Network
|
themeum
|
tutor_lms
|
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by user…
|
-
|
CVE-2021-24455
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196012
|
4.8 |
MEDIUM
Network
|
properfraction
|
profilepress
|
The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and …
|
-
|
CVE-2021-24450
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196013
|
4.8 |
MEDIUM
Network
|
cozmoslabs
|
profile_builder
|
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to us…
|
-
|
CVE-2021-24448
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196014
|
4.8 |
MEDIUM
Network
|
taxopress
|
taxopress
|
The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payloa…
|
-
|
CVE-2021-24444
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196015
|
7.2 |
HIGH
Network
|
optimocha
|
speed_booster_pack
|
The Speed Booster Pack ? PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PH…
|
CWE-94
Code Injection
|
CVE-2021-24430
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196016
|
4.8 |
MEDIUM
Network
|
yandex
|
yandex_turbo
|
The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving and outputing them in the admin dashboard, leading to an Authenticated Stored Cro…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24428
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196017
|
5.4 |
MEDIUM
Network
|
kainelabs
|
youzify
|
The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authent…
|
-
|
CVE-2021-24443
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196018
|
4.8 |
MEDIUM
Network
|
premio
|
mystickymenu
|
The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight pr…
|
-
|
CVE-2021-24425
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196019
|
4.8 |
MEDIUM
Network
|
never5
|
related_posts
|
The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Si…
|
-
|
CVE-2021-24482
|
2024-11-21 14:53 |
2021-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196020
|
8.8 |
HIGH
Network
|
include_me_project
|
include_me
|
The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to Remote Code Execution (RCE) of the system due to log poisoning and therefore po…
|
-
|
CVE-2021-24453
|
2024-11-21 14:53 |
2021-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|