1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-24615
微信打赏(Wechat Reward) Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.

CVE-2021-24538
Current Book Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-79 1 PoC

The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.

CVE-2021-24309
Weekly Schedule Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags and cause a stored XSS issue

CVE-2021-20164
Trendnet AC2600 TEW-827DRU Windows
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Usernames and passwords for all smb users are revealed in plaintext on the smbserver.asp page.

CVE-2021-24895
Cybersoldier Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-24931
Secure Copy Content Protection and Content Locking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.2%
2021 CWE-89 2 PoCs

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

CVE-2021-24904
Mortgage Calculators WP Web Windows
N/A
UNKNOWN
EPSS
3.0%
2021 CWE-79 1 PoC

The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-24671
MX Time Zone Clocks Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_clocks shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-24735
Compact WP Audio Player Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.

CVE-2021-24850
Insert Pages Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. It can be used by users with a role as low as Contributor to perform Cross-Site Scripting attacks by storing the payload/s in another post's custom fields.

CVE-2021-25120
Easy Social Feed Pro Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.6%
2021 CWE-79 1 PoC

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

CVE-2021-24859
User meta shortcodes Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-284 1 PoC

The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes

CVE-2021-24600
WP Dialog Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them in pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-24910
Transposh WordPress Translation Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.6%
2021 CWE-79 1 PoC

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24368
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to open a malicious link

CVE-2021-24410
తెలుగు బైబిల్ వచనములు Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers to make a logged in admin change the settings, as well as add malicious verses containing JavaScript code in them, leading to Stored XSS issues

CVE-2021-24896
Caldera Forms – More Than Contact Forms Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-24720
Business Directory Plugin | GeoDirectory Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-79 1 PoC

The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).

CVE-2021-25089
UpdraftPlus WordPress Backup Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting

CVE-2021-24984
WPFront User Role Editor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting