|
195891
|
7.5 |
HIGH
Network
|
themeum
|
qubely
|
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
|
NVD-CWE-Other
|
CVE-2021-24916
|
2024-11-21 14:54 |
2023-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195892
|
4.8 |
MEDIUM
Network
|
lesterchan
|
wp-postratings
|
The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though…
|
CWE-352
Origin Validation Error
|
CVE-2021-25117
|
2024-11-21 14:54 |
2024-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195893
|
7.2 |
HIGH
Network
|
menu_item_visibility_control_project
|
menu_item_visibility_control
|
The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execut…
|
NVD-CWE-Other
|
CVE-2021-24942
|
2024-11-21 14:54 |
2022-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195894
|
4.3 |
MEDIUM
Network
|
metagauss
|
download_plugin
|
The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the…
|
-
|
CVE-2021-25059
|
2024-11-21 14:54 |
2022-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195895
|
6.1 |
MEDIUM
Network
|
premium-themes
|
cryptocurrency_pricing_list_and_ticker
|
The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage parameter before outputting it back in pages where its shortcode is embed, leadin…
|
-
|
CVE-2021-25044
|
2024-11-21 14:54 |
2022-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195896
|
4.8 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfilt…
|
-
|
CVE-2021-25066
|
2024-11-21 14:54 |
2022-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195897
|
4.8 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_h…
|
CWE-79
Cross-site Scripting
|
CVE-2021-25056
|
2024-11-21 14:54 |
2022-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195898
|
6.5 |
MEDIUM
Network
|
bestwebsoft
|
rating
|
The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such…
|
-
|
CVE-2021-25121
|
2024-11-21 14:54 |
2022-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195899
|
6.1 |
MEDIUM
Network
|
oceanwp
|
ocean_extra
|
The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
|
-
|
CVE-2021-25104
|
2024-11-21 14:54 |
2022-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195900
|
4.8 |
MEDIUM
Network
|
google_xml_sitemaps_project
|
google_xml_sitemaps
|
The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting a…
|
-
|
CVE-2021-25088
|
2024-11-21 14:54 |
2022-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|