|
197031
|
4.8 |
MEDIUM
Network
|
cozmoslabs
|
translatepress
|
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still all…
|
-
|
CVE-2021-24610
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197032
|
4.8 |
MEDIUM
Network
|
hu-manity
|
cookie_notice_\&_compliance_for_gdpr_\/_ccpa
|
The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high pri…
|
-
|
CVE-2021-24569
|
2024-11-21 14:53 |
2021-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197033
|
9.8 |
CRITICAL
Network
|
schiocco
|
support_board_-_chat_and_help_desk
|
The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before…
|
-
|
CVE-2021-24741
|
2024-11-21 14:53 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197034
|
7.2 |
HIGH
Network
|
simple_schools_staff_directory_project
|
simple_schools_staff_directory
|
The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitr…
|
-
|
CVE-2021-24663
|
2024-11-21 14:53 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197035
|
6.1 |
MEDIUM
Network
|
limit_login_attempts_project
|
limit_login_attempts
|
The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputtin…
|
-
|
CVE-2021-24657
|
2024-11-21 14:53 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197036
|
5.4 |
MEDIUM
Network
|
gutenslider
|
gutenslider
|
The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor to perform Cross-Site…
|
-
|
CVE-2021-24640
|
2024-11-21 14:53 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197037
|
8.1 |
HIGH
Network
|
ffw
|
omgf
|
The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary…
|
-
|
CVE-2021-24639
|
2024-11-21 14:53 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197038
|
9.1 |
CRITICAL
Network
|
ffw
|
omgf
|
The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file …
|
-
|
CVE-2021-24638
|
2024-11-21 14:53 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197039
|
5.4 |
MEDIUM
Network
|
fontsplugin
|
fonts
|
The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scrip…
|
-
|
CVE-2021-24637
|
2024-11-21 14:53 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197040
|
8.1 |
HIGH
Network
|
print_my_blog_project
|
print_my_blog
|
The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved …
|
-
|
CVE-2021-24636
|
2024-11-21 14:53 |
2021-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|