|
197021
|
5.4 |
MEDIUM
Network
|
status301
|
coolclock
|
The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks
|
-
|
CVE-2021-24670
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197022
|
9.8 |
CRITICAL
Network
|
podlove
|
podlove_podcast_publisher
|
The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an…
|
-
|
CVE-2021-24666
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197023
|
4.3 |
MEDIUM
Network
|
wpxpo
|
postx_-_gutenberg_blocks_for_post_grid
|
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post…
|
NVD-CWE-Other
|
CVE-2021-24661
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197024
|
5.4 |
MEDIUM
Network
|
wpxpo
|
postx_-_gutenberg_blocks_for_post_grid
|
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting at…
|
-
|
CVE-2021-24660
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197025
|
5.4 |
MEDIUM
Network
|
wpxpo
|
postx_-_gutenberg_blocks_for_post_grid
|
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.
|
-
|
CVE-2021-24659
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197026
|
6.5 |
MEDIUM
Network
|
wpxpo
|
postx_-_gutenberg_blocks_for_post_grid
|
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify…
|
-
|
CVE-2021-24652
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197027
|
5.4 |
MEDIUM
Network
|
wp_map_block_project
|
wp_map_block
|
The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting at…
|
-
|
CVE-2021-24643
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197028
|
5.4 |
MEDIUM
Network
|
wpzoom
|
recipe_card_blocks_for_gutenberg_\&_elementor
|
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredi…
|
-
|
CVE-2021-24634
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197029
|
4.3 |
MEDIUM
Network
|
wpdeveloper
|
countdown_block
|
The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents d…
|
-
|
CVE-2021-24633
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197030
|
6.1 |
MEDIUM
Network
|
wpzoom
|
recipe_card_blocks_for_gutenberg_\&_elementor
|
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
|
-
|
CVE-2021-24632
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|