Search Results (18006 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-25089 1 Updraftplus 1 Updraftplus 2024-11-21 6.1 Medium
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting
CVE-2021-25088 1 Google Xml Sitemaps Project 1 Google Xml Sitemaps 2024-11-21 4.8 Medium
The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2021-25086 1 Advanced Page Visit Counter Project 1 Advanced Page Visit Counter 2024-11-21 6.1 Medium
The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it
CVE-2021-25085 1 Pluginus 1 Woocommerce Products Filter 2024-11-21 6.1 Medium
The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2021-25084 1 Bracketspace 1 Advanced Cron Manager 2024-11-21 4.3 Medium
The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example
CVE-2021-25083 1 Roundupwp 1 Registrations For The Events Calendar 2024-11-21 6.1 Medium
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
CVE-2021-25082 1 Sygnoos 1 Popup Builder 2024-11-21 8.8 High
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR
CVE-2021-25081 1 Wpgooglemap 1 Wp Google Map 2024-11-21 6.5 Medium
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
CVE-2021-25080 1 Crmperks 1 Contact Form Entries 2024-11-21 6.1 Medium
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
CVE-2021-25079 1 Crmperks 1 Contact Form Entries 2024-11-21 6.1 Medium
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page
CVE-2021-25078 1 Wpaffiliatemanager 1 Affiliates Manager 2024-11-21 6.1 Medium
The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.
CVE-2021-25077 1 Visser 1 Store Toolkit For Woocommerce 2024-11-21 6.1 Medium
The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting
CVE-2021-25076 1 Wedevs 1 Wp User Frontend 2024-11-21 8.8 High
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site Scripting
CVE-2021-25075 1 Wpdevart 1 Duplicate Page Or Post 2024-11-21 3.5 Low
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues
CVE-2021-25074 1 Webp Converter For Media Project 1 Webp Converter For Media 2024-11-21 6.1 Medium
The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue
CVE-2021-25073 1 Webmaster-source 1 Wp125 2024-11-21 8.8 High
The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack
CVE-2021-25072 1 Nextscripts 1 Social Networks Auto Poster 2024-11-21 6.5 Medium
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack
CVE-2021-25071 1 Inpsyde 1 Akismet Privacy Policies 2024-11-21 6.1 Medium
The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2021-25070 1 Stopbadbots 1 Block And Stop Bad Bots 2024-11-21 9.8 Critical
The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue
CVE-2021-25068 1 Dpl 1 Sync Woocommerce Product Feed To Google Shopping 2024-11-21 7.2 High
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard