|
196181
|
5.4 |
MEDIUM
Network
|
weekly_schedule_project
|
weekly_schedule
|
The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags …
|
-
|
CVE-2021-24309
|
2024-11-21 14:52 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196182
|
7.5 |
HIGH
Network
|
apache
|
wicket
|
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is no…
|
CWE-200
Information Exposure
|
CVE-2021-23937
|
2024-11-21 14:52 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196183
|
4.8 |
MEDIUM
Network
|
autoptimize
|
autoptimize
|
The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-…
|
-
|
CVE-2021-24332
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196184
|
5.4 |
MEDIUM
Network
|
lifterlms
|
lifterlms
|
The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when ou…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24308
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196185
|
8.8 |
HIGH
Network
|
aioseo
|
all_in_one_seo
|
The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-24307
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196186
|
5.4 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link t…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24306
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196187
|
6.1 |
MEDIUM
Network
|
targetfirst
|
watcheezy
|
The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a …
|
-
|
CVE-2021-24305
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196188
|
5.4 |
MEDIUM
Network
|
neox
|
hana_flv_player
|
The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.
|
-
|
CVE-2021-24302
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196189
|
5.4 |
MEDIUM
Network
|
bluemedicinelabs
|
hotjar_connecticator
|
The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly veri…
|
-
|
CVE-2021-24301
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196190
|
6.1 |
MEDIUM
Network
|
pickplugins
|
product_slider_for_woocommerce
|
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Sit…
|
-
|
CVE-2021-24300
|
2024-11-21 14:52 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|