|
197371
|
6.1 |
MEDIUM
Network
|
clogica
|
seo_redirection_plugin
|
The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or…
|
-
|
CVE-2021-24325
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197372
|
6.5 |
MEDIUM
Network
|
clogica
|
all_404_redirect_to_homepage
|
The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisat…
|
-
|
CVE-2021-24324
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197373
|
4.8 |
MEDIUM
Network
|
woocommerce
|
woocommerce
|
When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XS…
|
-
|
CVE-2021-24323
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197374
|
4.8 |
MEDIUM
Network
|
givewp
|
givewp
|
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Background Image field of its Stripe Checkout Setting and Logo field in its Email s…
|
-
|
CVE-2021-24315
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197375
|
9.8 |
CRITICAL
Network
|
boostifythemes
|
goto
|
The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injecti…
|
-
|
CVE-2021-24314
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197376
|
6.1 |
MEDIUM
Network
|
catzsoft
|
redi_restaurant_reservation
|
The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24299
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197377
|
6.1 |
MEDIUM
Network
|
de-baat
|
store_locator_plus
|
There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.
|
-
|
CVE-2021-24290
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197378
|
8.8 |
HIGH
Network
|
de-baat
|
store_locator_plus
|
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any sit…
|
-
|
CVE-2021-24289
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197379
|
6.1 |
MEDIUM
Network
|
acymailing
|
acymailing
|
When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing pag…
|
-
|
CVE-2021-24288
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197380
|
7.5 |
HIGH
Network
|
cleantalk
|
spam_protection\ _antispam\ _firewall
|
It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log func…
|
-
|
CVE-2021-24295
|
2024-11-21 14:52 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|