|
196391
|
9.8 |
CRITICAL
Network
|
publishpress
|
capabilities
|
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's setting…
|
CWE-352 CWE-862
Origin Validation Error Missing Authorization
|
CVE-2021-25032
|
2024-11-21 14:54 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196392
|
9.8 |
CRITICAL
Network
|
posimyth
|
the_plus_addons_for_elementor
|
The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL statement, which could l…
|
-
|
CVE-2021-24949
|
2024-11-21 14:54 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196393
|
7.5 |
HIGH
Network
|
posimyth
|
the_plus_addons_for_elementor
|
The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retri…
|
CWE-74
Injection
|
CVE-2021-24948
|
2024-11-21 14:54 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196394
|
6.1 |
MEDIUM
Network
|
booking_calendar_project
|
booking_calendar
|
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
|
CWE-79
Cross-site Scripting
|
CVE-2021-25040
|
2024-11-21 14:54 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196395
|
8.8 |
HIGH
Network
|
e-dynamics
|
events_made_easy
|
The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any auth…
|
CWE-89
SQL Injection
|
CVE-2021-25030
|
2024-11-21 14:54 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196396
|
6.1 |
MEDIUM
Network
|
ideabox
|
powerpack_addons_for_elementor
|
The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site …
|
CWE-79
Cross-site Scripting
|
CVE-2021-25027
|
2024-11-21 14:54 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196397
|
7.2 |
HIGH
Network
|
optimocha
|
speed_booster_pack
|
The Speed Booster Pack ? PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_table_name parameter before using it in a SQL statement to convert the related ta…
|
CWE-89
SQL Injection
|
CVE-2021-25023
|
2024-11-21 14:54 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196398
|
6.1 |
MEDIUM
Network
|
updraftplus
|
updraftplus
|
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to R…
|
CWE-79
Cross-site Scripting
|
CVE-2021-25022
|
2024-11-21 14:54 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196399
|
4.9 |
MEDIUM
Network
|
ffw
|
optimize_my_google_fonts
|
The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary fo…
|
CWE-22
Path Traversal
|
CVE-2021-25021
|
2024-11-21 14:54 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196400
|
4.9 |
MEDIUM
Network
|
daan
|
complete_analytics_optimization_suite
|
The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary…
|
CWE-22
Path Traversal
|
CVE-2021-25020
|
2024-11-21 14:54 |
2022-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|