|
196111
|
5.4 |
MEDIUM
Network
|
keyword_meta_project
|
keyword_meta
|
The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furtherm…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2021-24611
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196112
|
5.4 |
MEDIUM
Network
|
geminilabs
|
site_reviews
|
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the …
|
-
|
CVE-2021-24603
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196113
|
5.4 |
MEDIUM
Network
|
wpfront
|
wpfront_notification_bar
|
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks eve…
|
-
|
CVE-2021-24601
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196114
|
6.1 |
MEDIUM
Network
|
wp-webhooks
|
email_encoder
|
The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping o…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24599
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196115
|
5.4 |
MEDIUM
Network
|
dna88
|
highlight
|
The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is …
|
-
|
CVE-2021-24591
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196116
|
5.4 |
MEDIUM
Network
|
gdprinfo
|
cookie_notice_\&_consent_banner_for_gdpr_\&_ccpa_compliance
|
The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customi…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24590
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196117
|
6.1 |
MEDIUM
Network
|
cozyvision
|
sms_alert_order_notifications
|
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
|
-
|
CVE-2021-24588
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196118
|
5.4 |
MEDIUM
Network
|
addtoany
|
addtoany_share_buttons
|
The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cro…
|
-
|
CVE-2021-24568
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196119
|
5.4 |
MEDIUM
Network
|
trumani
|
stop_spammers
|
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scri…
|
-
|
CVE-2021-24517
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196120
|
5.4 |
MEDIUM
Network
|
web-settler
|
form_builder
|
The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting …
|
-
|
CVE-2021-24513
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|