| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2021-24915 | Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Email Address Disclosure | Unknown | Contest Gallery – Photo Contest Plugin for WordPress | 超危 | - | 2021-11-29 08:25:50 | Deep Dive |
| CVE-2021-24749 | URL Shortify < 1.5.1 - Arbitrary Link/Group Deletion via CSRF | Unknown | URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress | 中危 | - | 2021-11-29 08:25:32 | Deep Dive |
| CVE-2021-36919 | WordPress Awesome Support plugin <= 6.0.6 - Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities | Awesome Support | Awesome Support (WordPress plugin) | Medium | 6.1 | 2021-11-26 16:41:30 | Deep Dive |
| CVE-2021-36843 | WordPress Floating Social Media Icon plugin <= 4.3.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability | Acurax Technologies | Floating Social Media Icon (WordPress plugin) | Medium | 4.8 | 2021-11-26 16:35:15 | Deep Dive |
| CVE-2021-36916 | WordPress Hide My WP premium plugin <= 6.2.3 - Unauthenticated SQL injection (SQLi) vulnerability | wpWave | Hide My WP (WordPress plugin) | High | 8.6 | 2021-11-24 16:29:41 | Deep Dive |
| CVE-2021-36917 | WordPress Hide My WP premium plugin <= 6.2.3 - Unauthenticated Plugin Deactivation vulnerability | wpWave | Hide My WP (WordPress plugin) | Medium | 6.5 | 2021-11-24 16:19:09 | Deep Dive |
| CVE-2021-24875 | eCommerce Product Catalog for WordPress < 3.0.39 - Reflected Cross-Site Scripting | Unknown | eCommerce Product Catalog Plugin for WordPress | 中危 | - | 2021-11-23 19:16:16 | Deep Dive |
| CVE-2021-36884 | WordPress Backup Migration plugin <= 1.1.5 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability | Backupbliss | Backup Migration (WordPress plugin) | Medium | 4.8 | 2021-11-19 18:19:34 | Deep Dive |
| CVE-2021-43408 | Duplicate Post WordPress Plugin SQL Injection Vulnerability | Copy Delete Posts | Duplicate Post WordPress Plugin | Medium | 6.5 | 2021-11-19 15:41:33 | Deep Dive |
| CVE-2021-24537 | Similar Posts <= 3.1.5 - Admin+ Arbitrary PHP Code Execution | Unknown | Similar Posts – Best Related Posts Plugin for WordPress | 高危 | - | 2021-11-08 17:34:43 | Deep Dive |
| CVE-2021-24884 | Formidable Form Builder < 4.09.05 - Unauthenticated Stored Cross-Site Scripting | Unknown | Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress | 超危 | - | 2021-10-25 13:20:59 | Deep Dive |
| CVE-2021-24608 | Formidable Form Builder < 5.0.07 - Admin+ Stored Cross-Site Scripting | Unknown | Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress | 中危 | - | 2021-10-25 13:20:45 | Deep Dive |
| CVE-2021-36869 | WordPress Ivory Search plugin <= 4.6.6 - Reflected Cross-Site Scripting (XSS) vulnerability | Ivory Search | Ivory Search (WordPress plugin) | Medium | 4.8 | 2021-10-21 20:18:28 | Deep Dive |
| CVE-2021-24702 | LearnPress < 4.1.3.1 - Multiple Admin+ Stored Cross-Site Scripting | Unknown | LearnPress – WordPress LMS Plugin | 中危 | - | 2021-10-18 13:46:00 | Deep Dive |
| CVE-2021-24684 | PDF Light Viewer < 1.4.12 - Authenticated Command Injection | Unknown | WordPress PDF Light Viewer Plugin | 高危 | - | 2021-10-18 13:45:58 | Deep Dive |
| CVE-2021-24415 | Polo Video Gallery <= 1.2 - Contributor+ Stored Cross-Site Scripting | Unknown | Polo Video Gallery – Best wordpress video gallery plugin | 中危 | - | 2021-10-18 13:45:40 | Deep Dive |
| CVE-2021-24712 | Appointment Hour Booking – WordPress Booking Plugin < 1.3.17 - Authenticated Stored XSS | Unknown | Appointment Hour Booking – WordPress Booking Plugin | 中危 | - | 2021-10-11 10:45:47 | Deep Dive |
| CVE-2021-24691 | Quiz And Survey Master < 7.3.2 - Admin+ Stored Cross-Site Scripting | Unknown | Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress | 中危 | - | 2021-10-11 10:45:42 | Deep Dive |
| CVE-2021-24576 | Easy Accordion < 2.0.22 - Authenticated Stored XSS | Unknown | Easy Accordion – Best Accordion FAQ Plugin for WordPress | 中危 | - | 2021-10-11 10:45:31 | Deep Dive |
| CVE-2021-36850 | WordPress Media File Renamer – Auto & Manual Rename plugin <= 5.1.9 - Cross-Site Request Forgery (CSRF) vulnerability | Meow Apps | Media File Renamer – Auto & Manual Rename (WordPress plugin) | Medium | 5.4 | 2021-10-04 16:57:04 | Deep Dive |