|
196421
|
6.1 |
MEDIUM
Network
|
brevo
|
newsletter\ _smtp\ _email_marketing_and_subscribe
|
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to…
|
-
|
CVE-2021-24874
|
2024-11-21 14:53 |
2022-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196422
|
5.4 |
MEDIUM
Network
|
wpchill
|
remove_footer_credit
|
The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored X…
|
-
|
CVE-2021-24446
|
2024-11-21 14:53 |
2022-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196423
|
5.4 |
MEDIUM
Network
|
supportcandy
|
supportcandy
|
The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Script…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24880
|
2024-11-21 14:53 |
2022-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196424
|
8.8 |
HIGH
Network
|
supportcandy
|
supportcandy
|
The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers …
|
CWE-352
Origin Validation Error
|
CVE-2021-24879
|
2024-11-21 14:53 |
2022-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196425
|
6.1 |
MEDIUM
Network
|
supportcandy
|
supportcandy
|
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected C…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24878
|
2024-11-21 14:53 |
2022-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196426
|
6.5 |
MEDIUM
Network
|
supportcandy
|
supportcandy
|
The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via…
|
CWE-352
Origin Validation Error
|
CVE-2021-24843
|
2024-11-21 14:53 |
2022-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196427
|
7.5 |
HIGH
Network
|
supportcandy
|
supportcandy
|
The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tic…
|
CWE-862
Missing Authorization
|
CVE-2021-24839
|
2024-11-21 14:53 |
2022-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196428
|
4.8 |
MEDIUM
Network
|
wpmanageninja
|
ninja_tables
|
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfi…
|
-
|
CVE-2021-24900
|
2024-11-21 14:53 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196429
|
4.3 |
MEDIUM
Network
|
bplugins
|
document_embedder
|
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-24868
|
2024-11-21 14:53 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196430
|
5.3 |
MEDIUM
Network
|
bplugins
|
document_embedder
|
The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-24775
|
2024-11-21 14:53 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|