|
197841
|
6.5 |
MEDIUM
Network
|
querysol
|
redirection_for_contact_form_7
|
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress reposit…
|
-
|
CVE-2021-24279
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197842
|
7.5 |
HIGH
Network
|
querysol
|
redirection_for_contact_form_7
|
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.
|
-
|
CVE-2021-24278
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197843
|
5.4 |
MEDIUM
Network
|
wpuslugi
|
rss_for_yandex_turbo
|
The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its ???????? settings tab before outputting them back in the page, leading to authenticated stored…
|
-
|
CVE-2021-24277
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197844
|
8.8 |
HIGH
Network
|
wp-buy
|
login_as_user_or_customer_\(user_switching\)
|
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including …
|
NVD-CWE-Other
|
CVE-2021-24195
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197845
|
8.8 |
HIGH
Network
|
wp-buy
|
login_protection_-_limit_failed_login_attempts
|
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (includ…
|
NVD-CWE-Other
|
CVE-2021-24194
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197846
|
8.8 |
HIGH
Network
|
wp-buy
|
visitor_traffic_real_time_statistics
|
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a spe…
|
NVD-CWE-Other
|
CVE-2021-24193
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197847
|
8.8 |
HIGH
Network
|
sitemap_project
|
sitemap
|
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the W…
|
NVD-CWE-Other
|
CVE-2021-24192
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197848
|
8.8 |
HIGH
Network
|
wpshopmart
|
coming_soon_page_\&_maintenance_mode
|
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (inclu…
|
NVD-CWE-Other
|
CVE-2021-24191
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197849
|
8.8 |
HIGH
Network
|
wp-buy
|
conditional_marketing_mailer
|
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including …
|
NVD-CWE-Other
|
CVE-2021-24190
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197850
|
8.8 |
HIGH
Network
|
wp-buy
|
captchinoo
|
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (inc…
|
NVD-CWE-noinfo
|
CVE-2021-24189
|
2024-11-21 14:52 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|