Export limit exceeded: 37079 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (37079 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-24891 1 Elementor 1 Website Builder 2024-11-21 6.1 Medium
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
CVE-2021-24762 1 Getperfectsurvey 1 Perfect Survey 2024-11-21 9.8 Critical
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.
CVE-2021-24737 1 Gvectors 1 Wpdiscuz 2024-11-21 4.8 Medium
The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2021-24720 1 Ayecode 1 Geodirectory 2024-11-21 5.4 Medium
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
CVE-2021-24712 1 Dwbooster 1 Appointment Hour Booking 2024-11-21 5.4 Medium
The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.
CVE-2021-24711 1 Tipsandtricks-hq 1 Software License Manager 2024-11-21 8.8 High
The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack
CVE-2021-24709 1 Awplife 1 Weather Effect 2024-11-21 4.8 Medium
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues
CVE-2021-24692 1 Tipsandtricks-hq 1 Simple Download Monitor 2024-11-21 6.5 Medium
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
CVE-2021-24691 1 Expresstech 1 Quiz And Survey Master 2024-11-21 4.8 Medium
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2021-24690 1 Kibokolabs 1 Chained Quiz 2024-11-21 5.4 Medium
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
CVE-2021-24683 1 Awplife 1 Weather Effect 2024-11-21 5.4 Medium
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
CVE-2021-24681 1 Duplicatepro 1 Duplicate Page 2024-11-21 4.8 Medium
The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2021-24656 1 Wpbrigade 1 Simple Social Buttons 2024-11-21 4.8 Medium
The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2021-24655 1 Wpusermanager 1 Wp User Manager 2024-11-21 7.5 High
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.
CVE-2021-24651 1 Ays-pro 1 Poll Maker 2024-11-21 7.5 High
The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.
CVE-2021-24577 1 Wpdevart 1 Coming Soon And Maintenance Mode 2024-11-21 5.4 Medium
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.
CVE-2021-24576 1 Techearty 1 Easy Accordion 2024-11-21 5.4 Medium
The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.
CVE-2021-24546 1 Extendify 1 Editorskit 2024-11-21 8.8 High
The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code
CVE-2021-24545 1 Wp Html Author Bio Project 1 Wp Html Author Bio 2024-11-21 5.4 Medium
The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.
CVE-2021-24353 1 Wpdeveloper 1 Simple 301 Redirects 2024-11-21 8.8 High
The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.