|
195991
|
4.9 |
MEDIUM
Network
|
seur_oficial_project
|
seur_oficial
|
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server wi…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2021-25004
|
2024-11-21 14:54 |
2022-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195992
|
6.5 |
MEDIUM
Network
|
etoilewebdesign
|
ultimate_product_catalog
|
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call the…
|
CWE-352
Origin Validation Error
|
CVE-2021-24993
|
2024-11-21 14:54 |
2022-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195993
|
6.5 |
MEDIUM
Network
|
thinkupthemes
|
responsive_vector_maps
|
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any …
|
CWE-352 CWE-434
Origin Validation Error Unrestricted Upload of File with Dangerous Type
|
CVE-2021-24947
|
2024-11-21 14:54 |
2022-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195994
|
6.5 |
MEDIUM
Network
|
rearrange_woocommerce_products_project
|
rearrange_woocommerce_products
|
The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_order AJAX action, nor validation and escaping when inserting user data in SQL st…
|
NVD-CWE-Other
|
CVE-2021-24928
|
2024-11-21 14:54 |
2022-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195995
|
6.5 |
MEDIUM
Network
|
creativityjuice
|
labtools
|
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitra…
|
-
|
CVE-2021-25097
|
2024-11-21 14:54 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195996
|
7.5 |
HIGH
Network
|
ylefebvre
|
link_library
|
The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request
|
-
|
CVE-2021-25093
|
2024-11-21 14:54 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195997
|
6.5 |
MEDIUM
Network
|
ylefebvre
|
link_library
|
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack
|
-
|
CVE-2021-25092
|
2024-11-21 14:54 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195998
|
6.1 |
MEDIUM
Network
|
ylefebvre
|
link_library
|
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
|
-
|
CVE-2021-25091
|
2024-11-21 14:54 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195999
|
6.1 |
MEDIUM
Network
|
updraftplus
|
updraftplus
|
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflecte…
|
-
|
CVE-2021-25089
|
2024-11-21 14:54 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196000
|
6.1 |
MEDIUM
Network
|
pluginus
|
woocommerce_products_filter
|
The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting
|
-
|
CVE-2021-25085
|
2024-11-21 14:54 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|