Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-25080 | 1 Crmperks | 1 Contact Form Entries | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
|
|||||
| CVE-2021-25079 | 1 Crmperks | 1 Contact Form Entries | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page
|
|||||
| CVE-2021-25078 | 1 Wpaffiliatemanager | 1 Affiliates Manager | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.
|
|||||
| CVE-2021-25077 | 1 Visser | 1 Store Toolkit For Woocommerce | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25071 | 1 Inpsyde | 1 Akismet Privacy Policies | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25067 | 1 Pluginops | 1 Landing Page | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.
|
|||||
| CVE-2021-25066 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
|
|||||
| CVE-2021-25065 | 1 Smashballoon | 1 Smash Balloon Social Post Feed | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.
|
|||||
| CVE-2021-25063 | 1 Cf7skins | 1 Contact Form 7 Skins | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25062 | 1 Villatheme | 1 Orders Tracking For Woocommerce | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25061 | 1 Wpbookingsystem | 1 Wp Booking System | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.
|
|||||
| CVE-2021-25060 | 1 Fivestarplugins | 1 Five Star Business Profile And Schema | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues
|
|||||
| CVE-2021-25058 | 1 The Buffer Button Project | 1 The Buffer Button | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within the Twitter username to mention text field.
|
|||||
| CVE-2021-25057 | 1 Translationexchange | 1 Translation Exchange | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings.
|
|||||
| CVE-2021-25056 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
|
|||||
| CVE-2021-25055 | 1 Feedwordpress Project | 1 Feedwordpress | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
|
|||||
| CVE-2021-25050 | 1 Wpchill | 1 Remove Footer Credit | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
|
|||||
| CVE-2021-25049 | 1 Mobileeventsmanager | 1 Mobile Events Manager | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
|
|||||
| CVE-2021-25048 | 1 King-theme | 1 Kingcomposer | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them
|
|||||
| CVE-2021-25047 | 1 10web | 1 10websocial | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users
|
|||||
| CVE-2021-25046 | 1 Webnus | 1 Modern Events Calendar Lite | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.
|
|||||
| CVE-2021-25044 | 1 Premium-themes | 1 Cryptocurrency Pricing List And Ticker | 2024-11-21 | N/A | 6.1 MEDIUM |
|
The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage parameter before outputting it back in pages where its shortcode is embed, leading to a Reflected Cross-Site Scripting issue
|
|||||
| CVE-2021-25043 | 1 Pluginus | 1 Woocommerce Currency Switcher | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
|
|||||
| CVE-2021-25041 | 1 10web | 1 Photo Gallery | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action
|
|||||
| CVE-2021-25040 | 1 Booking Calendar Project | 1 Booking Calendar | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25039 | 1 Obtaininfotech | 1 Multisite Content Copier\/updater | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
|
|||||
| CVE-2021-25038 | 1 Obtaininfotech | 1 Multisite User Sync\/unsync | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
|
|||||
| CVE-2021-25035 | 1 Revmakx | 1 Backup And Staging By Wp Time Capsule | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25034 | 1 Wp User Project | 1 Wp User | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues
|
|||||
| CVE-2021-25031 | 1 Oxilab | 1 Image Hover Effects Ultimate | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25029 | 1 Cluevo | 1 Learning Management System | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
|
|||||
| CVE-2021-25027 | 1 Ideabox | 1 Powerpack Addons For Elementor | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
|
|||||
| CVE-2021-25026 | 1 Patreon | 1 Patreon Wordpress | 2024-11-21 | 3.5 LOW | 5.5 MEDIUM |
|
The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
|
|||||
| CVE-2021-25024 | 1 Theeventscalendar | 1 Eventcalendar | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues
|
|||||
| CVE-2021-25019 | 1 Squirrly | 1 Seo Plugin By Squirrly Seo | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25017 | 1 Themeum | 1 Tutor Lms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25016 | 1 Premio | 2 Chaty, Chaty Pro | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
|
|||||
| CVE-2021-25015 | 1 Mycred | 1 Mycred | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue
|
|||||
| CVE-2021-25012 | 1 Popozure | 1 Pz-linkcard | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-Site Scripting issues
|
|||||
| CVE-2021-25008 | 1 Codesnippets | 1 Code Snippets | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue
|
|||||