Vulnerabilities (CVE)

Filtered by CWE-79
Total 37280 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25057 1 Translationexchange 1 Translation Exchange 2024-11-21 3.5 LOW 5.4 MEDIUM
The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings.
CVE-2021-25056 1 Ninjaforms 1 Ninja Forms 2024-11-21 3.5 LOW 4.8 MEDIUM
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2021-25055 1 Feedwordpress Project 1 Feedwordpress 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
CVE-2021-25050 1 Wpchill 1 Remove Footer Credit 2024-11-21 3.5 LOW 4.8 MEDIUM
The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
CVE-2021-25049 1 Mobileeventsmanager 1 Mobile Events Manager 2024-11-21 3.5 LOW 4.8 MEDIUM
The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2021-25048 1 King-theme 1 Kingcomposer 2024-11-21 3.5 LOW 5.4 MEDIUM
The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creating profile, allowing any authenticated users to create arbitrary ones, with Cross-Site Scripting payloads in them
CVE-2021-25047 1 10web 1 10websocial 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users
CVE-2021-25046 1 Webnus 1 Modern Events Calendar Lite 2024-11-21 3.5 LOW 5.4 MEDIUM
The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.
CVE-2021-25044 1 Premium-themes 1 Cryptocurrency Pricing List And Ticker 2024-11-21 N/A 6.1 MEDIUM
The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage parameter before outputting it back in pages where its shortcode is embed, leading to a Reflected Cross-Site Scripting issue
CVE-2021-25043 1 Pluginus 1 Woocommerce Currency Switcher 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
CVE-2021-25041 1 10web 1 Photo Gallery 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action
CVE-2021-25040 1 Booking Calendar Project 1 Booking Calendar 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2021-25039 1 Obtaininfotech 1 Multisite Content Copier\/updater 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
CVE-2021-25038 1 Obtaininfotech 1 Multisite User Sync\/unsync 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
CVE-2021-25035 1 Revmakx 1 Backup And Staging By Wp Time Capsule 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2021-25034 1 Wp User Project 1 Wp User 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues
CVE-2021-25031 1 Oxilab 1 Image Hover Effects Ultimate 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
CVE-2021-25029 1 Cluevo 1 Learning Management System 2024-11-21 3.5 LOW 4.8 MEDIUM
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
CVE-2021-25027 1 Ideabox 1 Powerpack Addons For Elementor 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
CVE-2021-25026 1 Patreon 1 Patreon Wordpress 2024-11-21 3.5 LOW 5.5 MEDIUM
The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed