Total
15175 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24849 | 1 Wclovers | 1 Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections | |||||
CVE-2021-24848 | 1 Frenify | 1 Mediamatic | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection | |||||
CVE-2021-24847 | 1 Wp-buy | 1 Seo Redirection-301 Redirect Manager | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed | |||||
CVE-2021-24846 | 1 Ni Woocommerce Custom Order Status Project | 1 Ni Woocommerce Custom Order Status | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber | |||||
CVE-2021-24844 | 1 Wpaffiliatemanager | 1 Affiliates Manager | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue | |||||
CVE-2021-24835 | 1 Wclovers | 1 Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacks | |||||
CVE-2021-24829 | 1 Wp-buy | 1 Visitor Traffic Real Time Statistics | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue | |||||
CVE-2021-24827 | 1 Asgaros | 1 Asgaros Forum | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue | |||||
CVE-2021-24791 | 1 Draftpress | 1 Header Footer Code Manager | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections | |||||
CVE-2021-24778 | 1 Wpaffiliatefeed | 1 Tradetracker-store | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. | |||||
CVE-2021-24777 | 1 Hotscot | 1 Contact Form | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection. | |||||
CVE-2021-24774 | 1 Wpchill | 1 Check \& Log Email | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues | |||||
CVE-2021-24772 | 1 Xwp | 1 Stream | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue. | |||||
CVE-2021-24769 | 1 Permalink Manager Lite Project | 1 Permalink Manager Lite | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injection | |||||
CVE-2021-24762 | 1 Getperfectsurvey | 1 Perfect Survey | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection. | |||||
CVE-2021-24758 | 1 Email Log Project | 1 Email Log | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections | |||||
CVE-2021-24755 | 1 Mycred | 1 Mycred | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user | |||||
CVE-2021-24754 | 1 Mainwp | 1 Mainwp Child Reports | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue | |||||
CVE-2021-24753 | 1 Starfish | 1 Rich Review | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue | |||||
CVE-2021-24750 | 1 Wp Visitor Statistics \(real Time Traffic\) Project | 1 Wp Visitor Statistics \(real Time Traffic\) | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks |