|
197611
|
8.8 |
HIGH
Network
|
tipsandtricks-hq
|
software_license_manager
|
The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack
|
-
|
CVE-2021-24711
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197612
|
4.8 |
MEDIUM
Network
|
awplife
|
weather_effect
|
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting …
|
-
|
CVE-2021-24709
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197613
|
4.8 |
MEDIUM
Network
|
expresstech
|
quiz_and_survey_master
|
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scr…
|
-
|
CVE-2021-24691
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197614
|
5.4 |
MEDIUM
Network
|
kibokolabs
|
chained_quiz
|
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
|
-
|
CVE-2021-24690
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197615
|
5.4 |
MEDIUM
Network
|
awplife
|
weather_effect
|
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting i…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2021-24683
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197616
|
4.8 |
MEDIUM
Network
|
duplicatepro
|
duplicate_page
|
The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-S…
|
-
|
CVE-2021-24681
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197617
|
4.8 |
MEDIUM
Network
|
wpbrigade
|
simple_social_buttons
|
The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allo…
|
-
|
CVE-2021-24656
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197618
|
7.5 |
HIGH
Network
|
ays-pro
|
poll_maker
|
The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possib…
|
-
|
CVE-2021-24651
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197619
|
5.4 |
MEDIUM
Network
|
wpdevart
|
coming_soon_and_maintenance_mode
|
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode …
|
-
|
CVE-2021-24577
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197620
|
5.4 |
MEDIUM
Network
|
techearty
|
easy_accordion
|
The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.
|
-
|
CVE-2021-24576
|
2024-11-21 14:53 |
2021-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|