|
196621
|
4.8 |
MEDIUM
Network
|
strategy11
|
formidable_form_builder
|
The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cro…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24608
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196622
|
6.1 |
MEDIUM
Network
|
jquery-reply-to-comment_project
|
jquery-reply-to-comment
|
The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor sanitise or escape its 'Quote String' and 'Reply String' settings before outputtin…
|
-
|
CVE-2021-24543
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196623
|
5.4 |
MEDIUM
Network
|
motopress
|
motopress-slider-lite
|
The Responsive WordPress Slider WordPress plugin through 2.2.0 does not sanitise and escape some of the Slider options, allowing Cross-Site Scripting payloads to be set in them. Furthermore, as by de…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24544
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196624
|
4.8 |
MEDIUM
Network
|
origincode
|
video_gallery
|
The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues
|
-
|
CVE-2021-24515
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196625
|
4.8 |
MEDIUM
Network
|
vfbpro
|
visual_form_builder
|
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24514
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196626
|
4.8 |
MEDIUM
Network
|
emarketdesign
|
request_a_quote
|
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even w…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24489
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196627
|
8.8 |
HIGH
Network
|
sanskruti
|
st-daily-tip
|
The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and was also lacking sanitisation as well as escaping…
|
-
|
CVE-2021-24487
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196628
|
4.8 |
MEDIUM
Network
|
wp-special-textboxes_project
|
wp-special-textboxes
|
The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the u…
|
-
|
CVE-2021-24485
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196629
|
5.4 |
MEDIUM
Network
|
video_player_for_youtube_project
|
video_player_for_youtube
|
The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24414
|
2024-11-21 14:53 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196630
|
5.4 |
MEDIUM
Network
|
pdf_viewer_block_for_gutenberg_project
|
pdf_viewer_block_for_gutenberg
|
The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2021-24760
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|