|
197811
|
8.8 |
HIGH
Network
|
wow-estore
|
side_menu
|
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue
|
CWE-89
SQL Injection
|
CVE-2021-24580
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197812
|
8.8 |
HIGH
Network
|
bold-themes
|
bold_page_builder
|
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any validation or sanitisation, which could lead to a P…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-24579
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197813
|
5.4 |
MEDIUM
Network
|
wpmanageninja
|
fluentsmtp
|
The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SM…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24528
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197814
|
6.1 |
MEDIUM
Network
|
sharethis
|
dashboard_for_google_analytics
|
The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the p…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24438
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197815
|
6.1 |
MEDIUM
Network
|
realfavicongenerator
|
favicon_by_realfavicongenerator
|
The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scrip…
|
-
|
CVE-2021-24437
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197816
|
4.8 |
MEDIUM
Network
|
erident_custom_login_and_dashboard_project
|
erident_custom_login_and_dashboard
|
The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24658
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197817
|
8.8 |
HIGH
Network
|
hmplugin
|
hm_multiple_roles
|
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2021-24602
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197818
|
4.8 |
MEDIUM
Network
|
simple_banner_project
|
simple_banner
|
The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfilt…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24574
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197819
|
5.4 |
MEDIUM
Network
|
harmonicdesign
|
hd_quiz
|
The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues
|
CWE-79
Cross-site Scripting
|
CVE-2021-24571
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197820
|
8.8 |
HIGH
Network
|
contact_form_7_captcha_project
|
contact_form_7_captcha
|
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2021-24565
|
2024-11-21 14:53 |
2021-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|