Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24971 1 Magnigenie 1 Wp Responsive Menu 2022-03-08 3.5 LOW 5.4 MEDIUM
The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update AJAX action, as well as do not sanitise and escape some of the data submitted. As a result, any authenticated, such as subscriber could update the plugin's settings and perform Cross-Site Scripting attacks against all visitor and users on the frontend
CVE-2021-24933 1 Bootstrapped 1 Dynamic Widgets 2022-03-08 3.5 LOW 5.4 MEDIUM
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue
CVE-2021-25081 1 Wpgooglemap 1 Wp Google Map 2022-03-08 4.3 MEDIUM 6.5 MEDIUM
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
CVE-2022-23135 1 Zte 4 Zxhn F477, Zxhn F477 Firmware, Zxhn F677 and 1 more 2022-03-08 5.5 MEDIUM 6.5 MEDIUM
There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.
CVE-2022-23912 1 Accesspressthemes 1 Ap Custom Testimonial 2022-03-08 4.3 MEDIUM 6.1 MEDIUM
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting
CVE-2022-23911 1 Accesspressthemes 1 Ap Custom Testimonial 2022-03-08 6.5 MEDIUM 7.2 HIGH
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection
CVE-2022-0412 1 Templateinvaders 1 Ti Woocommerce Wishlist 2022-03-08 7.5 HIGH 9.8 CRITICAL
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks
CVE-2022-0411 1 Asgaros 1 Asgaros Forum 2022-03-08 6.5 MEDIUM 8.8 HIGH
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection
CVE-2021-25042 1 Plugins-market 1 Wp Visitor Statistics \(real Time Traffic\) 2022-03-08 3.5 LOW 5.4 MEDIUM
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack of validation, sanitisation and escaping, users could set a malicious value and perform Cross-Site Scripting attacks against logged in admin
CVE-2021-24994 1 Wpvivid 1 Migration\, Backup\, Staging 2022-03-08 4.3 MEDIUM 6.1 MEDIUM
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
CVE-2021-25010 1 Postsnippets 1 Post Snippets 2022-03-08 6.8 MEDIUM 9.6 CRITICAL
The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues
CVE-2022-0385 1 Crazy Bone Project 1 Crazy Bone 2022-03-08 4.3 MEDIUM 6.1 MEDIUM
The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from when displaying them back in the log dashboard, leading to an unauthenticated Stored Cross-Site scripting
CVE-2021-25034 1 Wp User Project 1 Wp User 2022-03-08 4.3 MEDIUM 6.1 MEDIUM
The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues
CVE-2022-0383 1 Ljapps 1 Wp Review Slider 2022-03-08 6.5 MEDIUM 7.2 HIGH
The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks
CVE-2022-0377 1 Thimpress 1 Learnpress 2022-03-08 3.5 LOW 4.3 MEDIUM
Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming and cropping of the image. As a result of this request, the name of the user-supplied image is changed with a MD5 value. This process can be conducted only when type of the image is JPG or PNG. An attacker can use this vulnerability in order to rename an arbitrary image file. By doing this, they could destroy the design of the web site.
CVE-2022-0360 1 Smackcoders 1 Easy Drag And Drop All Import 2022-03-08 3.5 LOW 4.8 MEDIUM
The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped imported comments, which could allow high privilege users to import malicious ones (either intentionnaly or not) and lead to Stored Cross-Site Scripting issues
CVE-2022-0345 1 Madewithfuel 1 Customize Wordpress Emails And Alerts 2022-03-08 4.0 MEDIUM 4.3 MEDIUM
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).
CVE-2021-25112 1 I-plugins 1 Whmcs Bridge 2022-03-08 4.3 MEDIUM 6.1 MEDIUM
The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting
CVE-2022-23650 1 Gravitl 1 Netmaker 2022-03-08 9.0 HIGH 8.8 HIGH
Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard-coded cryptographic key in the code base which can be exploited to run admin commands on a remote server if the exploiter know the address and username of the admin. This effects the server (netmaker) component, and not clients. This has been patched in Netmaker v0.8.5, v0.9.4, and v0.10.0. There are currently no known workarounds.
CVE-2021-4222 1 Maxfoundry 1 Wp-paginate 2022-03-08 3.5 LOW 4.8 MEDIUM
The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed