|
196211
|
8.8 |
HIGH
Network
|
ays-pro
|
survey_maker
|
The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the g…
|
-
|
CVE-2021-24459
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196212
|
8.8 |
HIGH
Network
|
ays-pro
|
popup_box
|
The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements …
|
-
|
CVE-2021-24458
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196213
|
8.8 |
HIGH
Network
|
ays-pro
|
portfolio_responsive_gallery
|
The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Po…
|
-
|
CVE-2021-24457
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196214
|
7.2 |
HIGH
Network
|
ays-pro
|
quiz_maker
|
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin …
|
CWE-89
SQL Injection
|
CVE-2021-24456
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196215
|
5.4 |
MEDIUM
Network
|
themeum
|
tutor_lms
|
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by user…
|
-
|
CVE-2021-24455
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196216
|
4.8 |
MEDIUM
Network
|
properfraction
|
profilepress
|
The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.8 did not sanitise or escape some of its settings before saving them and …
|
-
|
CVE-2021-24450
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196217
|
4.8 |
MEDIUM
Network
|
cozmoslabs
|
profile_builder
|
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to us…
|
-
|
CVE-2021-24448
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196218
|
4.8 |
MEDIUM
Network
|
taxopress
|
taxopress
|
The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payloa…
|
-
|
CVE-2021-24444
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196219
|
7.2 |
HIGH
Network
|
optimocha
|
speed_booster_pack
|
The Speed Booster Pack ? PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PH…
|
CWE-94
Code Injection
|
CVE-2021-24430
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196220
|
4.8 |
MEDIUM
Network
|
yandex
|
yandex_turbo
|
The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving and outputing them in the admin dashboard, leading to an Authenticated Stored Cro…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24428
|
2024-11-21 14:53 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|