|
196891
|
5.4 |
MEDIUM
Network
|
schiocco
|
support_board
|
The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authe…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24807
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196892
|
4.3 |
MEDIUM
Network
|
gvectors
|
wpdiscuz
|
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary c…
|
CWE-352
Origin Validation Error
|
CVE-2021-24806
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196893
|
4.3 |
MEDIUM
Network
|
wp_survey_plus_project
|
wp_survey_plus
|
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, …
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2021-24801
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196894
|
6.1 |
MEDIUM
Network
|
androidbubbles
|
wp_header_images
|
The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cross-Site Scripting is…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24798
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196895
|
7.2 |
HIGH
Network
|
draftpress
|
header_footer_code_manager
|
The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets …
|
CWE-89
SQL Injection
|
CVE-2021-24791
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196896
|
6.5 |
MEDIUM
Network
|
batch_cat_project
|
batch_cat
|
The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subs…
|
NVD-CWE-Other
|
CVE-2021-24788
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196897
|
6.5 |
MEDIUM
Network
|
publishpress
|
post_expirator
|
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.
|
CWE-863
Incorrect Authorization
|
CVE-2021-24783
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196898
|
6.5 |
MEDIUM
Network
|
fullworks
|
redirect_404_error_page_to_homepage_or_custom_page_with_logs
|
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete …
|
-
|
CVE-2021-24767
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196899
|
6.5 |
MEDIUM
Network
|
404_to_301_project
|
404_to_301
|
The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delet…
|
-
|
CVE-2021-24766
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196900
|
8.8 |
HIGH
Network
|
wclovers
|
frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible
|
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor p…
|
CWE-89
SQL Injection
|
CVE-2021-24835
|
2024-11-21 14:53 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|