|
196441
|
7.2 |
HIGH
Network
|
acf-extended
|
advanced_custom_fields\
|
The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue
|
-
|
CVE-2021-24865
|
2024-11-21 14:53 |
2022-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196442
|
7.2 |
HIGH
Network
|
accesspressthemes
|
wp_cookie_user_info
|
The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin …
|
-
|
CVE-2021-24858
|
2024-11-21 14:53 |
2022-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196443
|
4.3 |
MEDIUM
Network
|
wp_post_page_clone_project
|
wp_post_page_clone
|
The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.
|
CWE-863
Incorrect Authorization
|
CVE-2021-24733
|
2024-11-21 14:53 |
2022-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196444
|
8.8 |
HIGH
Network
|
tipsandtricks-hq
|
simple_download_monitor
|
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log di…
|
-
|
CVE-2021-24696
|
2024-11-21 14:53 |
2022-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196445
|
5.4 |
MEDIUM
Network
|
tipsandtricks-hq
|
simple_download_monitor
|
The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24694
|
2024-11-21 14:53 |
2022-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196446
|
4.8 |
MEDIUM
Network
|
updraftplus
|
updraftplus
|
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and lead…
|
-
|
CVE-2021-24423
|
2024-11-21 14:53 |
2022-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196447
|
6.1 |
MEDIUM
Network
|
navz
|
acf_photo_gallery_field
|
The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute…
|
-
|
CVE-2021-24909
|
2024-11-21 14:53 |
2022-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196448
|
6.1 |
MEDIUM
Network
|
bologer
|
anycomment
|
The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Red…
|
-
|
CVE-2021-24838
|
2024-11-21 14:53 |
2022-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196449
|
7.2 |
HIGH
Network
|
metagauss
|
registrationmagic
|
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could l…
|
-
|
CVE-2021-24862
|
2024-11-21 14:53 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196450
|
7.5 |
HIGH
Network
|
stars_rating_project
|
stars_rating
|
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment das…
|
CWE-20
Improper Input Validation
|
CVE-2021-24893
|
2024-11-21 14:53 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|