Total
15902 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24946 | 1 Webnus | 1 Modern Events Calendar Lite | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue | |||||
CVE-2021-24943 | 1 Roundupwp | 1 Registrations For The Events Calendar | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection. | |||||
CVE-2021-24931 | 1 Ays-pro | 1 Secure Copy Content Protection And Content Locking | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection. | |||||
CVE-2021-24919 | 1 Wickedplugins | 1 Wicked Folders | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection | |||||
CVE-2021-24915 | 1 Contest Gallery | 1 Contest Gallery | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address | |||||
CVE-2021-24889 | 1 Ninjaforms | 1 Ninja Forms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks | |||||
CVE-2021-24877 | 1 Mainwp | 1 Mainwp Child | 2024-11-21 | 6.0 MEDIUM | 7.2 HIGH |
The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed | |||||
CVE-2021-24866 | 1 Wpdataaccess | 1 Wp Data Access | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion | |||||
CVE-2021-24865 | 1 Acf-extended | 1 Advanced Custom Fields\ | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue | |||||
CVE-2021-24864 | 1 Wpscan | 1 Wp Cloudy | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue | |||||
CVE-2021-24863 | 1 Stopbadbots | 1 Block And Stop Bad Bots | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection | |||||
CVE-2021-24862 | 1 Metagauss | 1 Registrationmagic | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue | |||||
CVE-2021-24861 | 1 Quotes Collection Project | 1 Quotes Collection | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection | |||||
CVE-2021-24860 | 1 Bannersky | 1 Bsk Pdf Manager | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue | |||||
CVE-2021-24858 | 1 Accesspressthemes | 1 Wp Cookie User Info | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection | |||||
CVE-2021-24849 | 1 Wclovers | 1 Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections | |||||
CVE-2021-24848 | 1 Frenify | 1 Mediamatic | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection | |||||
CVE-2021-24847 | 1 Wp-buy | 1 Seo Redirection-301 Redirect Manager | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed | |||||
CVE-2021-24846 | 1 Ni Woocommerce Custom Order Status Project | 1 Ni Woocommerce Custom Order Status | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber | |||||
CVE-2021-24844 | 1 Wpaffiliatemanager | 1 Affiliates Manager | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue |