|
196821
|
6.1 |
MEDIUM
Network
|
wpeden
|
shiny_buttons
|
The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and es…
|
-
|
CVE-2021-24792
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196822
|
4.3 |
MEDIUM
Network
|
contact_form_advanced_database_project
|
contact_form_advanced_database
|
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any auth…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2021-24790
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196823
|
6.5 |
MEDIUM
Network
|
wp_admin_logo_changer_project
|
wp_admin_logo_changer
|
The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.
|
-
|
CVE-2021-24784
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196824
|
4.8 |
MEDIUM
Network
|
flex_local_fonts_project
|
flex_local_fonts
|
The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when …
|
-
|
CVE-2021-24782
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196825
|
4.3 |
MEDIUM
Network
|
single_post_exporter_project
|
single_post_exporter
|
The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and giv…
|
CWE-352
Origin Validation Error
|
CVE-2021-24780
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196826
|
4.8 |
MEDIUM
Network
|
inspirational_quote_rotator_project
|
inspirational_quote_rotator
|
The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issue…
|
-
|
CVE-2021-24771
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196827
|
6.1 |
MEDIUM
Network
|
wp_system_log_project
|
wp_system_log
|
The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow u…
|
-
|
CVE-2021-24756
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196828
|
7.2 |
HIGH
Network
|
cleverplugins
|
seo_booster
|
The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_ajax" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly…
|
-
|
CVE-2021-24747
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196829
|
4.8 |
MEDIUM
Network
|
basixonline
|
nex-forms
|
The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape some of its settings as well as form fields before outputting them in attribute…
|
-
|
CVE-2021-24705
|
2024-11-21 14:53 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196830
|
9.8 |
CRITICAL
Network
|
wpdataaccess
|
wp_data_access
|
The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbi…
|
-
|
CVE-2021-24866
|
2024-11-21 14:53 |
2021-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|