|
196981
|
5.3 |
MEDIUM
Network
|
find_my_blocks_project
|
find_my_blocks
|
The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.
|
-
|
CVE-2021-24677
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196982
|
6.5 |
MEDIUM
Network
|
onedesigns
|
one_user_avatar
|
The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in us…
|
-
|
CVE-2021-24675
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196983
|
5.4 |
MEDIUM
Network
|
onedesigns
|
one_user_avatar
|
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Script…
|
-
|
CVE-2021-24672
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196984
|
6.5 |
MEDIUM
Network
|
scroll_banner_project
|
scroll_banner
|
The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to m…
|
-
|
CVE-2021-24642
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196985
|
4.8 |
MEDIUM
Network
|
emarketdesign
|
customer_service_software_\&_support_ticket_system
|
The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users t…
|
-
|
CVE-2021-24622
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196986
|
6.1 |
MEDIUM
Network
|
gamepress_project
|
gamepress
|
The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in multiple Game Option pages, leading to Reflected Cross-Site Scripting issues
|
-
|
CVE-2021-24617
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196987
|
5.4 |
MEDIUM
Network
|
wechat_reward_project
|
wechat_reward
|
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perfo…
|
-
|
CVE-2021-24615
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196988
|
4.8 |
MEDIUM
Network
|
sociable_project
|
sociable
|
The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scri…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24612
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196989
|
6.5 |
MEDIUM
Network
|
wp_cookie_choice_project
|
wp_cookie_choice
|
The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a…
|
-
|
CVE-2021-24595
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196990
|
4.8 |
MEDIUM
Network
|
planso
|
planso_forms
|
The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes, allowing high privilege users such as admin to set XSS payload in it, even wh…
|
-
|
CVE-2021-24516
|
2024-11-21 14:53 |
2021-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|