Vulnerabilities (CVE)

Filtered by CWE-79
Total 37249 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24522 1 Properfraction 1 Profilepress 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.
CVE-2021-24519 1 Vikwp 1 Car Rental Management System 2024-11-21 3.5 LOW 4.8 MEDIUM
The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS payload in it, leading to an authenticated Stored Cross-Site Scripting issue
CVE-2021-24518 1 Wpfront 1 Notification Bar 2024-11-21 3.5 LOW 4.8 MEDIUM
The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
CVE-2021-24517 1 Trumani 1 Stop Spammers 2024-11-21 3.5 LOW 5.4 MEDIUM
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed
CVE-2021-24516 1 Planso 1 Planso Forms 2024-11-21 3.5 LOW 4.8 MEDIUM
The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes, allowing high privilege users such as admin to set XSS payload in it, even when the unfiltered_html is disallowed, leading to an Authenticated Stored Cross-Site Scripting issue.
CVE-2021-24515 1 Origincode 1 Video Gallery 2024-11-21 3.5 LOW 4.8 MEDIUM
The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues
CVE-2021-24514 1 Vfbpro 1 Visual Form Builder 2024-11-21 3.5 LOW 4.8 MEDIUM
The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed
CVE-2021-24513 1 Web-settler 1 Form Builder 2024-11-21 3.5 LOW 5.4 MEDIUM
The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed
CVE-2021-24512 1 Videowhisper 1 Video Posts Webcam Recorder 2024-11-21 3.5 LOW 5.4 MEDIUM
The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos.
CVE-2021-24509 1 A3rev 1 Page View Count 2024-11-21 3.5 LOW 5.4 MEDIUM
The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.
CVE-2021-24508 1 Smashballoon 1 Smash Balloon Social Post Feed 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.
CVE-2021-24505 1 Madeit 1 Forms 2024-11-21 3.5 LOW 5.4 MEDIUM
The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issues. The plugin was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the Forms "Add new" field.
CVE-2021-24504 1 Wplearnmanager 1 Wp Learn Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)
CVE-2021-24503 1 Thememason 1 Popular Brand Icons - Simple Icons 2024-11-21 3.5 LOW 5.4 MEDIUM
The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.
CVE-2021-24498 1 Dwbooster 1 Calendar Event Multi View 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.
CVE-2021-24496 1 Community Events Project 1 Community Events 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
CVE-2021-24495 1 Marmoset 1 Marmoset Viewer 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.
CVE-2021-24494 1 Deliciousbrains 1 Wp Offload Ses Lite 2024-11-21 3.5 LOW 5.4 MEDIUM
The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admin dashboard, such as the email's id, subject and recipient, which could lead to Stored Cross-Site Scripting issues when an attacker can control any of these fields, like the subject when filling a contact form for example. The XSS will be executed in the context of a logged in admin viewing the Activity tab of the plugin.
CVE-2021-24489 1 Emarketdesign 1 Request A Quote 2024-11-21 3.5 LOW 4.8 MEDIUM
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
CVE-2021-24488 1 Pickplugins 1 Post Grid 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues