1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-24979
Paid Memberships Pro Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2021 CWE-79 1 PoC

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-24546
Gutenberg Block Editor Toolkit – EditorsKit Web Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-94 1 PoC

The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code

CVE-2021-24166
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.

CVE-2021-24331
Smooth Scroll Page Up/Down Buttons Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them

CVE-2021-25084
Advanced Cron Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

CVE-2021-25064
Wow Countdowns – easily create any countdowns, counters and timers Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.

CVE-2021-24897
Add Subtitle Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with classic editor) when output in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

CVE-2021-24952
Conversios.io – Google Analytics and Google Shopping plugin for WooCommerce Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing any authenticated user to perform SQL injection attacks.

CVE-2021-24232
Advanced Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue

CVE-2021-24880
SupportCandy – Helpdesk & Support Ticket System Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

CVE-2021-24739
Logo Carousel – Logo Slider, Logo Showcase, and Clients Logo Gallery Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-639 1 PoC

The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature

CVE-2021-24178
Business Directory Plugin – Easy Listing Directories for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.

CVE-2021-24616
AddToAny Share Buttons Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-25066
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-24980
Gwolle Guestbook Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page

CVE-2021-29643
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.

CVE-2021-24746
Social Sharing Plugin – Sassy Social Share Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2021 CWE-79 1 PoC

The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back in onclick attributes when the "Enable 'More' icon" option is enabled (which is the default setting), leading to a Reflected Cross-Site Scripting issue.

CVE-2021-24289
Store Locator Plus for WordPress Web Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-269 1 PoC

There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.

CVE-2021-25088
XML Sitemaps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2021-24374
Jetpack – WP Security, Backup, Speed, & Growth Web Windows
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-639 1 PoC

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to comment on the images. A security vulnerability was found within the Jetpack Carousel module by nguyenhg_vcs that allowed the comments of non-published page/posts to be leaked.