|
196601
|
5.4 |
MEDIUM
Network
|
wpdownloadmanager
|
wordpress_download_manager
|
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack …
|
-
|
CVE-2021-24969
|
2024-11-21 14:54 |
2021-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196602
|
6.1 |
MEDIUM
Network
|
themehunk
|
contact_form_\&_lead_form_elementor_builder
|
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting att…
|
-
|
CVE-2021-24967
|
2024-11-21 14:54 |
2021-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196603
|
7.5 |
HIGH
Network
|
wpwax
|
directorist
|
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
|
-
|
CVE-2021-24981
|
2024-11-21 14:54 |
2021-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196604
|
6.1 |
MEDIUM
Network
|
adenion
|
blog2social
|
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Ref…
|
-
|
CVE-2021-24956
|
2024-11-21 14:54 |
2021-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196605
|
6.1 |
MEDIUM
Network
|
icegram
|
icegram
|
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputt…
|
-
|
CVE-2021-24941
|
2024-11-21 14:54 |
2021-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196606
|
4.8 |
MEDIUM
Network
|
fatcatapps
|
pixel_cat
|
The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disal…
|
-
|
CVE-2021-24972
|
2024-11-21 14:54 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196607
|
7.2 |
HIGH
Network
|
plugins360
|
all-in-one_video_gallery
|
The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Incl…
|
-
|
CVE-2021-24970
|
2024-11-21 14:54 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196608
|
6.1 |
MEDIUM
Network
|
profilepress
|
user_registration\ _login_form\ _user_profile_\&_membership
|
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back…
|
-
|
CVE-2021-24955
|
2024-11-21 14:54 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196609
|
6.1 |
MEDIUM
Network
|
profilepress
|
user_registration\ _login_form\ _user_profile_\&_membership
|
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an ad…
|
-
|
CVE-2021-24954
|
2024-11-21 14:54 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196610
|
9.8 |
CRITICAL
Network
|
thimpress
|
learnpress
|
The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Inj…
|
-
|
CVE-2021-24951
|
2024-11-21 14:54 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|