|
196611
|
6.1 |
MEDIUM
Network
|
yop-poll
|
yop-poll
|
The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
|
CWE-79
Cross-site Scripting
|
CVE-2021-24885
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196612
|
4.8 |
MEDIUM
Network
|
great-quotes_project
|
great-quotes
|
The Great Quotes WordPress plugin through 1.0.0 does not sanitise and escape the Quote and Author fields of its Quotes, which could allow high privilege users to perform Cross-Site Scripting attacks …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24785
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196613
|
6.5 |
MEDIUM
Network
|
wp_debugging_project
|
wp_debugging
|
The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by u…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2021-24779
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196614
|
7.2 |
HIGH
Network
|
wpchill
|
check_\&_log_email
|
The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL inject…
|
CWE-89
SQL Injection
|
CVE-2021-24774
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196615
|
7.2 |
HIGH
Network
|
permalink_manager_lite_project
|
permalink_manager_lite
|
The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injec…
|
CWE-89
SQL Injection
|
CVE-2021-24769
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196616
|
4.8 |
MEDIUM
Network
|
cimatti
|
contact_forms
|
The WordPress Contact Forms by Cimatti WordPress plugin before 1.4.12 does not sanitise and escape the Form Title before outputting it in some admin pages. which could allow high privilege users to p…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24744
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196617
|
9.6 |
CRITICAL
Network
|
strategy11
|
formidable_form_builder
|
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to explo…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2021-24884
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196618
|
5.4 |
MEDIUM
Network
|
easy_media_download_project
|
easy_media_download
|
The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Script…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24699
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196619
|
7.2 |
HIGH
Network
|
game-server-status_project
|
game-server-status
|
The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it in SQL statement, leading to an Authenticated SQL Injection in an admin page
|
CWE-89
SQL Injection
|
CVE-2021-24662
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196620
|
4.8 |
MEDIUM
Network
|
cookie-bar_project
|
cookie-bar
|
The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unf…
|
-
|
CVE-2021-24653
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|