|
196381
|
5.4 |
MEDIUM
Network
|
nickmomrik
|
simple_post
|
The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it does not escape these values when outputting to the browser leading to an Auth…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24567
|
2024-11-21 14:53 |
2024-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196382
|
8.8 |
HIGH
Network
|
pluginus
|
fox_-_currency_switcher_professional_for_woocommerce
|
The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.
|
NVD-CWE-Other
|
CVE-2021-24566
|
2024-11-21 14:53 |
2024-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196383
|
5.4 |
MEDIUM
Network
|
patrickposner
|
qyrr
|
The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, allowing for Cross-Site Scripting attacks. Furthermore, the data_uri_to_meta AJ…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24559
|
2024-11-21 14:53 |
2024-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196384
|
5.4 |
MEDIUM
Network
|
yukimichi
|
simple_sort\&search
|
The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24433
|
2024-11-21 14:53 |
2024-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196385
|
6.1 |
MEDIUM
Network
|
berocket
|
advanced_ajax_product_filters
|
The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue.
|
CWE-79
Cross-site Scripting
|
CVE-2021-24432
|
2024-11-21 14:53 |
2024-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196386
|
7.5 |
HIGH
Network
|
passster_project
|
passter
|
The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by …
|
NVD-CWE-Other
|
CVE-2021-24881
|
2024-11-21 14:53 |
2023-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196387
|
5.4 |
MEDIUM
Network
|
passster_project
|
passter
|
The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
|
-
|
CVE-2021-24837
|
2024-11-21 14:53 |
2023-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196388
|
9.8 |
CRITICAL
Network
|
wedevs
|
wp_user_frontend
|
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via w…
|
-
|
CVE-2021-24649
|
2024-11-21 14:53 |
2022-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196389
|
8.8 |
HIGH
Network
|
dplugins
|
scripts_organizer
|
The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action, available to both unauthenticated and authenticated users, and does not valid…
|
-
|
CVE-2021-24890
|
2024-11-21 14:53 |
2022-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196390
|
5.4 |
MEDIUM
Network
|
transposh
|
transposh_wordpress_translation
|
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. G…
|
-
|
CVE-2021-24912
|
2024-11-21 14:53 |
2022-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|