CVE-2021-24000 to CVE-2021-24999
797 CVEs with public proof-of-concept exploits.
- CVE-2021-240064 PoCsAn improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted…
- CVE-2021-240192 PoCsAn insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an…
- CVE-2021-240271 PoCA cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third…
- CVE-2021-240331 PoCreact-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a command string to…
- CVE-2021-240402 PoCsDue to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide…
- CVE-2021-240841 PoCWindows Mobile Device Management Information Disclosure Vulnerability
- CVE-2021-240851 PoCMicrosoft Exchange Server Spoofing Vulnerability
- CVE-2021-240864 PoCsWindows TCP/IP Denial of Service Vulnerability
- CVE-2021-240911 PoCWindows Camera Codec Pack Remote Code Execution Vulnerability
- CVE-2021-240931 PoCWindows Graphics Component Remote Code Execution Vulnerability
- CVE-2021-240961 PoCWindows Kernel Elevation of Privilege Vulnerability
- CVE-2021-240981 PoCWindows Console Driver Denial of Service Vulnerability
- CVE-2021-241231 PoCPowerPress < 8.3.8 - Authenticated Arbitrary File Upload leading to RCE
- CVE-2021-241241 PoCWP Shieldon 1.6.3 - Unauthenticated Cross-Site Scripting (XSS)
- CVE-2021-241251 PoCContact Form Submissions < 1.7.1 - Authenticated SQL Injection
- CVE-2021-241261 PoCEnvira Gallery Lite < 1.8.3.3 - Authenticated Stored Cross-Site Scripting
- CVE-2021-241271 PoCThirstyAffiliates < 3.9.3 - Authenticated Stored XSS
- CVE-2021-241281 PoCTeam Members < 5.0.4 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-241291 PoCThemify Portfolio Post < 1.1.6 - Authenticated Stored Cross-Site Scripting
- CVE-2021-241301 PoCWP Google Map Plugin < 4.1.5 - Authenticated SQL Injection
- CVE-2021-241311 PoCAnti-Spam by CleanTalk < 5.149 - Multiple Authenticated SQL Injections
- CVE-2021-241321 PoCSlider by 10Web < 1.2.36 - Multiple Authenticated SQL Injection
- CVE-2021-241331 PoCActiveCampaign < 8.0.2 - Cross-Site Request Forgery in Settings
- CVE-2021-241341 PoCConstant Contact Forms < 1.8.8 - Multiple Authenticated Stored XSS
- CVE-2021-241351 PoCWP Customer Reviews < 3.4.3 - Multiple Unauthenticated and Low Priv Authenticated Stored XSS
- CVE-2021-241361 PoCTestimonials Widget < 4.0.0 - Multiple Authenticated Stored XSS
- CVE-2021-241371 PoCBlog2Social: Social Media Auto Post & Scheduler < 6.3.1 - Authenticated SQL Injection
- CVE-2021-241381 PoCAdRotate < 5.8.4 - Authenticated SQL Injection
- CVE-2021-241391 PoCPhoto Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection
- CVE-2021-241457 PoCsModern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
- CVE-2021-241464 PoCsModern Events Calendar Lite < 5.16.5 - Unauthenticated Events Export
- CVE-2021-241471 PoCModern Events Calendar Lite < 5.16.5 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-241491 PoCModern Events Calendar Lite < 5.16.6 - Authenticated SQL Injection
- CVE-2021-241501 PoCLike Button Rating < 2.6.32 - Unauthenticated Full-Read SSRF
- CVE-2021-241511 PoCWP Editor < 1.2.7 - Authenticated SQL injection
- CVE-2021-241531 PoCYoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-241557 PoCsBackup Guard < 1.6.0 - Authenticated Arbitrary File Upload
- CVE-2021-241561 PoCTestimonial Rotator <= 3.0.3 - Authenticated Stored Cross-Site Scripting
- CVE-2021-241571 PoCOrbit Fox by ThemeIsle < 2.10.3 - Authenticated Stored Cross Site Scripting
- CVE-2021-241581 PoCOrbit Fox by ThemeIsle < 2.10.3 - Authenticated Privilege Escalation
- CVE-2021-241602 PoCsResponsive Menu 4.0.0 - 4.0.3 - Authenticated Arbitrary File Upload
- CVE-2021-241621 PoCResponsive Menu < 4.0.4 - CSRF to Settings Update
- CVE-2021-241631 PoCNinja Forms < 3.4.34 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure
- CVE-2021-241641 PoCNinja Forms < 3.4.34.1 - Authenticated OAuth Connection Key Disclosure
- CVE-2021-241652 PoCsNinja Forms < 3.4.34 - Administrator Open Redirect
- CVE-2021-241661 PoCNinja Forms < 3.4.34 - CSRF to OAuth Service Disconnection
- CVE-2021-241681 PoCEasy Contact Form Pro < 1.1.1.9 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-241694 PoCsAdvanced Order Export For WooCommerce < 3.1.8 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-241702 PoCsUser Profile Picture < 2.5.0 - Sensitive Information Disclosure
- CVE-2021-241742 PoCsDatabase Backups <= 1.2.2.6 - CSRF to Backup Download
- CVE-2021-241752 PoCsThe Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
- CVE-2021-241763 PoCsJH 404 Logger <= 1.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-241771 PoCWP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-241781 PoCBusiness Directory Plugin < 5.11.1 - Arbitrary Add/Edit/Delete Form Field to Stored XSS
- CVE-2021-241791 PoCBusiness Directory Plugin < 5.11 - Arbitrary File Upload to RCE
- CVE-2021-241801 PoCRelated Posts for WordPress < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-241811 PoCTutor LMS < 1.7.7 - SQL Injection via tutor_mark_answer_as_correct
- CVE-2021-241821 PoCTutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_answers_by_question
- CVE-2021-241831 PoCTutor LMS < 1.8.3 - SQL Injection via tutor_quiz_builder_get_question_form
- CVE-2021-241841 PoCTutor LMS < 1.7.7 - Unprotected AJAX including Privilege Escalation
- CVE-2021-241851 PoCTutor LMS < 1.7.7 - SQL Injection via tutor_place_rating
- CVE-2021-241862 PoCsTutor LMS < 1.8.3 - SQL Injection via tutor_answering_quiz_question/get_answer_by_id
- CVE-2021-241871 PoCSEO Redirection < 6.4 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-241881 PoCWP Content Copy Protection & No Right Click < 3.1.5 - Arbitrary Plugin Installation/Activation via Low Privilege User
- CVE-2021-241891 PoCCaptchinoo, Google recaptcha for admin login page < 2.4 - Arbitrary Plugin Installation/Activation via Low Privilege User
- CVE-2021-241901 PoCWooCommerce Conditional Marketing Mailer < 1.5.2 - Arbitrary Plugin Installation/Activation via Low Privilege User
- CVE-2021-241911 PoCWP Maintenance Mode & Site Under Construction < 1.8.2 - Arbitrary Plugin Installation/Activation via Low Privilege User
- CVE-2021-241921 PoCTree Sitemap < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege User
- CVE-2021-241931 PoCVisitor Traffic Real Time Statistics < 2.12 - Arbitrary Plugin Installation/Activation via Low Privilege User
- CVE-2021-241941 PoCLogin Protection - Limit Failed Login Attempts < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege User
- CVE-2021-241951 PoCLogin as User or Customer (User Switching) < 1.9 - Arbitrary Plugin Installation/Activation via Low Privilege User
- CVE-2021-241962 PoCsSocial Slider Widget < 1.8.5 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-242011 PoCElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Column Element
- CVE-2021-242021 PoCElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Heading Widget
- CVE-2021-242031 PoCElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Divider Widget
- CVE-2021-242041 PoCElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Accordion Widget
- CVE-2021-242051 PoCElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box Widget
- CVE-2021-242061 PoCElementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Image Box Widget
- CVE-2021-242071 PoCWP Page Builder < 1.2.4 - Insecure default configuration Allows Subscribers Editing Access to Posts
- CVE-2021-242092 PoCsWP Super Cache < 1.7.2 - Authenticated Remote Code Execution (RCE)
- CVE-2021-242102 PoCsPhastPress < 1.111 - Open Redirect
- CVE-2021-242111 PoCWordPress Related Posts <= 3.6.4 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-242122 PoCsWooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE
- CVE-2021-242134 PoCsGiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)
- CVE-2021-242142 PoCsOpenID Connect Generic Client 3.8.0-3.8.1 - Reflected Cross Site Scripting (XSS) via Login Error
- CVE-2021-242152 PoCsControlled Admin Access < 1.5.2 - Improper Access Control & Privilege Escalation
- CVE-2021-242161 PoCAll-in-One WP Migration < 7.41 - Admin+ Arbitrary File Upload to RCE
- CVE-2021-242171 PoCFacebook for WordPress < 3.0.0 - PHP Object Injection with POP Chain
- CVE-2021-242181 PoCFacebook for WordPress 3.0.0-3.0.3 - CSRF to Stored XSS and Settings Deletion
- CVE-2021-242192 PoCsAll Thrive Themes and Plugins - Unauthenticated Option Update
- CVE-2021-242202 PoCsAll Thrive Themes Legacy Themes < 2.0.0 - Unauthenticated Arbitrary File Upload and Option Deletion
- CVE-2021-242211 PoCQuiz And Survey Master < 7.1.12 - Authenticated SQL injection via shortcode
- CVE-2021-242221 PoCWP-Curricul Vitea Free <= 6.3 - Unauthenticated Arbitrary File Upload to RCE
- CVE-2021-242231 PoCN5 Upload Form <= 1.0 - Unauthenticated Arbitrary File Upload to RCE
- CVE-2021-242251 PoCAdvanced Booking Calendar < 1.6.7 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-242262 PoCsAccessAlly < 3.5.7 - $_SERVER Superglobal Leakage
- CVE-2021-242271 PoCPatreon WordPress < 1.7.0 - Unauthenticated Local File Disclosure
- CVE-2021-242321 PoCAdvanced Booking Calendar < 1.6.8 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-242331 PoCCooked Pro < 1.7.5.6 - Unauthenticated Reflected Cross Site Scripting (XSS)
- CVE-2021-242342 PoCsIvory Search < 4.6.1 - Reflected Cross Site Scripting (XSS)
- CVE-2021-242352 PoCsGoto - Tour & Travel < 2.0 - Unauthenticated Reflected XSS
- CVE-2021-242362 PoCsImagements <= 1.2.5 - Unauthenticated Arbitrary File Upload to RCE
- CVE-2021-242372 PoCsRealteo < 1.2.4 - Unauthenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-242381 PoCRealteo < 1.2.4 - Arbitrary Property Deletion via IDOR
- CVE-2021-242392 PoCsPie Register < 3.7.0.1 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-242411 PoCAdvanced Custom Field Pro < 5.9.1 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-242421 PoCTutor LMS < 1.8.8 - Authenticated Local File Inclusion
- CVE-2021-242431 PoCWPBakery Page Builder Clipboard < 4.5.6 - Subscriber+ Stored Cross-Site Scripting (XSS)
- CVE-2021-242441 PoCWPBakery Page Builder Clipboard < 4.5.8 - Unauthorised Arbitrary License Options Update
- CVE-2021-242454 PoCsStop Spammers < 2021.9 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-242461 PoCWorkScout Core < 1.3.4 - Authenticated Stored XSS & XFS
- CVE-2021-242472 PoCsContact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)
- CVE-2021-242481 PoCBusiness Directory Plugin < 5.11.1 - Authenticated PHP4 Upload to RCE
- CVE-2021-242491 PoCBusiness Directory Plugin < 5.11.2 - Arbitrary Listing Export
- CVE-2021-242501 PoCBusiness Directory Plugin < 5.11.2 - Authenticated Stored Cross-Site Scripting
- CVE-2021-242511 PoCBusiness Directory Plugin < 5.11.2 - Arbitrary Payment History Update
- CVE-2021-242521 PoCEvent Banner <= 1.3 - Arbitrary File Upload to RCE
- CVE-2021-242531 PoCClassyfrieds <= 3.8 - Authenticated Arbitrary File Upload to RCE
- CVE-2021-242541 PoCCollege Publisher Import <= 0.1 - Arbitrary File Upload to RCE
- CVE-2021-242723 PoCsFitness Calculators < 1.9.6 - Cross-Site Request Forgery to Cross-Site Scripting (XSS)
- CVE-2021-242743 PoCsUltimate Maps by Supsystic < 1.2.5 - Reflected Cross-Site scripting (XSS)
- CVE-2021-242754 PoCsPopup by Supsystic < 1.10.5 - Reflected Cross-Site scripting (XSS)
- CVE-2021-242764 PoCsContact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
- CVE-2021-242771 PoCRSS for Yandex Turbo < 1.30 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-242782 PoCsRedirection for Contact Form 7 < 2.3.4 - Unauthenticated Arbitrary Nonce Generation
- CVE-2021-242791 PoCRedirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Plugin Installation
- CVE-2021-242801 PoCRedirection for Contact Form 7 < 2.3.4 - Authenticated PHP Object Injection
- CVE-2021-242811 PoCRedirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Post Deletion
- CVE-2021-242831 PoCAccordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-242844 PoCsKaswara Modern VC Addons <= 3.0.1 - Unauthenticated Arbitrary File Upload
- CVE-2021-242852 PoCsCar Seller - Auto Classifieds Script <= 2.1.0 - Unauthenticated SQL Injection
- CVE-2021-242864 PoCsRedirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-242874 PoCsSelect All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-242882 PoCsAcyMailing < 7.5.0 - Unauthenticated Open Redirect
- CVE-2021-242913 PoCsPhoto Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS)
- CVE-2021-242931 PoCNextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-242941 PoCDSGVO All in one for WP < 4.0 - Unauthenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-242952 PoCsTime-based Blind SQL Injection in Spam protection, AntiSpam, FireWall by CleanTalk < 5.153.4
- CVE-2021-242961 PoCWP Customer Reviews < 3.5.6 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-242971 PoCGoto < 2.1 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-242983 PoCsSimple Giveaways < 2.36.2 - Unauthenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-242993 PoCsReDi Restaurant Reservations < 21.0426 - Unauthenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243003 PoCsPickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243011 PoCHotjar Connecticator <= 1.1.1 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243021 PoCHana Flv Player <= 3.1.3 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243032 PoCsJiangQie Official Website Mini Program < 1.1.1 - Authenticated SQL Injection
- CVE-2021-243041 PoCNewsmag < 5.0 - Unauthenticated Reflected Cross-site Scripting (XSS)
- CVE-2021-243051 PoCTarget First Plugin 2.0 - Unauthenticated Stored XSS via Licence Key
- CVE-2021-243061 PoCUltimate Member < 2.1.20 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-243072 PoCsAll in One SEO Pack < 4.1.0.2 - Admin RCE via unserialize
- CVE-2021-243083 PoCsLifterLMS < 4.21.1 - Authenticated Stored XSS in Edit Profile
- CVE-2021-243091 PoCWeekly Schedule < 3.4.3 - Authenticated Stored XSS
- CVE-2021-243101 PoCPhoto Gallery < 1.5.67 - Authenticated Stored Cross-Site Scripting via Gallery Title
- CVE-2021-243111 PoCExternal Media < 1.0.34 - Authenticated Arbitrary File Upload
- CVE-2021-243121 PoCWP Super Cache < 1.7.3 - Authenticated Remote Code Execution
- CVE-2021-243132 PoCsWP Prayer < 1.6.2 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243142 PoCsGoto < 2.1 - Unauthenticated Blind SQL Injection
- CVE-2021-243152 PoCsGive WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243164 PoCsMediumish <= 1.0.47 - Unauthenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-243172 PoCsListeo < 1.6.11 - Multiple XSS & XFS vulnerabilities
- CVE-2021-243182 PoCsListeo < 1.6.11 - Multiple Authenticated IDOR Vulnerabilities
- CVE-2021-243192 PoCsBello < 1.6.0 - Authenticated Cross-Site Scripting (XSS) and XFS
- CVE-2021-243203 PoCsBello < 1.6.0 - Unauthenticated Reflected XSS & XFS
- CVE-2021-243212 PoCsBello < 1.6.0 - Unauthenticated Blind SQL Injection
- CVE-2021-243222 PoCsDatabase Backup for WordPress < 2.4 - Authenticated Persistent Cross-Site Scripting (XSS)
- CVE-2021-243231 PoCWoocommerce < 5.2.0 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243241 PoC404 SEO Redirection <= 1.3 - CSRF to Stored Cross-Site Scripting (XSS)
- CVE-2021-243251 PoC404 SEO Redirection <= 1.3 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243261 PoCAll 404 Redirect to Homepage < 1.21 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-243271 PoCSEO Redirection < 6.4 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243283 PoCsWP Login Security and History <= 1.0 - CSRF to Stored Cross-Site Scripting (XSS)
- CVE-2021-243291 PoCWP Super Cache < 1.7.3 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243301 PoCFunnel Builder by CartFlows < 1.6.13 - Authenticated Stored XSS via FB Pixel ID and Google Analytics ID
- CVE-2021-243311 PoCSmooth Scroll Page Up/Down Buttons < 1.4 - Authenticated Stored XSS
- CVE-2021-243321 PoCAutoptimize < 2.8.4 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243332 PoCsContent Copy Protection & Prevent Image Save <= 1.3 - CSRF to Stored Cross-Site Scripting (XSS)
- CVE-2021-243341 PoCInstant Images WordPress Plugin < 4.4.0.1 - Authenticated Stored XSS & XFS
- CVE-2021-243352 PoCsCar Repair Services < 4.0 - Unauthenticated Reflected XSS & XFS
- CVE-2021-243362 PoCsFlightLog <= 3.0.2 - Authenticated (editor+) SQL Injection
- CVE-2021-243372 PoCsVideo Embed <= 1.0 - Authenticated (subscriber+) SQL Injection
- CVE-2021-243402 PoCsWP Statistics < 13.0.8 - Unauthenticated SQL Injection
- CVE-2021-243422 PoCsJNews < 8.0.6 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243431 PoCiFlyChat – WordPress Chat < 4.7.0 - Admin+ Stored Cross-Site Scripting (XSS)
- CVE-2021-243452 PoCsSendit WP Newsletter <= 2.5.1 - Authenticated (admin+) SQL Injection
- CVE-2021-243462 PoCsStock in & out <= 1.0.4 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243475 PoCsSP Project & Document Manager <2 4.22 - Authenticated Shell Upload
- CVE-2021-243482 PoCsSide Menu < 3.1.5 - Authenticated (admin+) SQL Injection
- CVE-2021-243491 PoCGallery From Files <= 1.6.0 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243512 PoCsThe Plus Addons for Elementor < 4.1.12 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243521 PoCSimple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Export
- CVE-2021-243531 PoCSimple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Import
- CVE-2021-243541 PoCSimple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin Installation
- CVE-2021-243551 PoCSimple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Update and Retrieve Wildcard Value
- CVE-2021-243562 PoCsSimple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin Activation
- CVE-2021-243571 PoCFooGallery < 2.0.35 - Authenticated Stored Cross-Site Scripting
- CVE-2021-243582 PoCsThe Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirect
- CVE-2021-243591 PoCThe Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email Sending
- CVE-2021-243601 PoCYes/No Chart < 1.0.12 - Authenticated (contributor+) Blind SQL Injection
- CVE-2021-243611 PoCGeoDirectory Location Manager < 2.1.0.10 - Multiple Unauthenticated SQL Injections
- CVE-2021-243621 PoCPhoto Gallery < 1.5.75 - Stored Cross-Site Scripting via Uploaded SVG
- CVE-2021-243631 PoCPhoto Gallery < 1.5.75 - File Upload Path Traversal
- CVE-2021-243642 PoCsJannah < 5.4.4 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243652 PoCsAdmin Columns Free (< 4.3.2) & Pro (< 5.5.2) - Authenticated Stored Cross-Site Scripting (XSS) in Custom Field
- CVE-2021-243661 PoCAdmin Columns Free < 4.3 & Pro < 5.5.1 - Admin+ Stored XSS in Label
- CVE-2021-243671 PoCWP Config File Editor <= 1.7.1 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243681 PoCQuiz And Survey Master < 7.1.18 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243691 PoCGetPaid < 2.3.4 - Authenticated Stored XSS
- CVE-2021-243705 PoCsFancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE
- CVE-2021-243712 PoCsRSVPMaker < 8.7.3 - Authenticated (admin+) SSRF
- CVE-2021-243721 PoCWP Hardening < 1.2.2 - Reflected XSS via URI
- CVE-2021-243731 PoCWP Hardening < 1.2.2 - Reflected XSS via historyvalue
- CVE-2021-243741 PoCJetpack < 9.8 - Carousel Module Non-Published Page/Post Attachment Comment Leak
- CVE-2021-243752 PoCsMotor theme < 3.1.0 - Local File Inclusion
- CVE-2021-243761 PoCAutoptimize < 2.7.8 - Arbitrary File Upload via "Import Settings"
- CVE-2021-243771 PoCAutoptimize < 2.7.8 - Race Condition leading to RCE
- CVE-2021-243781 PoCAutoptimize < 2.7.8 - Authenticated Stored XSS via File Upload
- CVE-2021-243791 PoCComments Like Dislike < 1.1.4 - Add Like/Dislike Bypass
- CVE-2021-243801 PoCShantz WordPress QOTD <= 1.2.2 - Arbitrary Setting Update via CSRF
- CVE-2021-243811 PoCNinjaForms < 3.5.8.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-243821 PoCSmart Slider 3 < 3.5.0.9 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243833 PoCsWP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-243841 PoCJoomSport < 5.1.8 - Unauthenticated PHP Object Injection
- CVE-2021-243851 PoCFilebird 4.7.3 - Unauthenticated SQL Injection
- CVE-2021-243861 PoCWP SVG Images < 3.4 - Authenticated (author+) Stored XSS via SVG
- CVE-2021-243872 PoCsReal Estate 7 < 3.1.1 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243881 PoCVik Rent Car < 1.1.7 - CSRF to Stored XSS
- CVE-2021-243892 PoCsFoodBakery < 2.2 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-243902 PoCsAlipay <= 3.7.2 - Authenticated SQL Injection
- CVE-2021-243912 PoCsCashtomer <= 1.0.0 - Authenticated SQL Injection
- CVE-2021-243922 PoCsWordPress Membership SwiftCloud.io <= 1.0 - Authenticated SQL Injection
- CVE-2021-243932 PoCsComment Highlighter <= 0.13 - Authenticated SQL Injection
- CVE-2021-243942 PoCsEasy Testimonial Manager <= 1.2.0 - Authenticated SQL Injection
- CVE-2021-243952 PoCsEmbed Youtube Video <= 1.0 - Authenticated SQL Injection
- CVE-2021-243962 PoCsGSEOR <= 1.3 - Authenticated SQL Injection
- CVE-2021-243972 PoCsMicroCopy <= 1.1.0 - Authenticated SQL Injection
- CVE-2021-243982 PoCsResponsive 3D Slider <= 1.2 - Authenticated SQL Injection
- CVE-2021-243992 PoCsThe Sorter <= 1.0 - Authenticated SQL Injection
- CVE-2021-244002 PoCsDisplay users <= 2.0.0 - Authenticated SQL Injection
- CVE-2021-244012 PoCsWP Domain Redirect <= 1.0 - Authenticated SQL Injection
- CVE-2021-244022 PoCsWP iCommerce <= 1.1.1 - Authenticated (contributor+) SQL Injection
- CVE-2021-244032 PoCsWordPress Page Contact <= 1.0 - Authenticated (editor+) SQL Injection
- CVE-2021-244042 PoCsWP-Board <= 1.1 (beta) - Unauthenticated SQL Injection
- CVE-2021-244053 PoCsEasy Cookie Policy <= 1.6.2 - Broken Access Control to Stored Cross-Site Scripting
- CVE-2021-244062 PoCswpForo Forum < 1.9.7 - Open Redirect
- CVE-2021-244072 PoCsJannah < 5.4.5 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-244081 PoCPrismatic < 2.8 - Contributor+ Stored XSS
- CVE-2021-244092 PoCsPrismatic < 2.8 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-244101 PoCTelugu Bible Verse Daily <= 1.0 - CSRF to Stored XSS
- CVE-2021-244111 PoCSocial Tape <= 1.0 - CSRF to Stored XSS
- CVE-2021-244121 PoCHtml5 Audio Player < 2.1.3 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-244131 PoCEasy Twitter Feed < 1.2 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-244141 PoCYT Player < 1.4 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-244181 PoCSmooth Scroll Page Up/Down Buttons <= 1.4 - Authenticated Stored XSS via psb_positioning
- CVE-2021-244191 PoCWP YouTube Lyte < 1.7.16 - Authenticated Stored XSS
- CVE-2021-244201 PoCRequest a Quote < 2.3.4 - Authenticated Stored XSS
- CVE-2021-244211 PoCWP JobSearch < 1.7.4 - Authenticated Stored XSS
- CVE-2021-244231 PoCUpdraftPlus < 1.16.59 - Admin+ Stored Cross-Site Scripting
- CVE-2021-244241 PoCWP Reset < 1.90 - Authenticated Stored XSS
- CVE-2021-244251 PoCmyStickymenu < 2.5.2 - Authenticated Stored XSS
- CVE-2021-244261 PoCBackup by 10Web <= 1.0.20 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-244271 PoCW3 Total Cache < 2.1.3 - Authenticated Stored XSS
- CVE-2021-244291 PoCSalon Booking System < 6.3.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-244301 PoCSpeed Booster Pack 4.2.0-beta - Authenticated (admin+) RCE
- CVE-2021-244311 PoCLanguage Bar Flags <= 1.0.8 - CSRF to Stored XSS
- CVE-2021-244321 PoCAdvanced AJAX Product Filters < 1.5.4.7 - Unauthenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-244331 PoCSimple Sort&Search <= 0.0.3 - Ccontributor+ Stored XSS
- CVE-2021-244341 PoCGlass <= 1.3.2 - CSRF to Stored Cross-Site Scripting (XSS)
- CVE-2021-244352 PoCsTitan Framework <= 1.12.1 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-244362 PoCsW3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)
- CVE-2021-244371 PoCFavicon by RealFaviconGenerator <= 1.3.20 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-244381 PoCShareThis Dashboard for Google Analytics < 2.5.2 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-244391 PoCBrowser Screenshots < 1.7.6 - Contributor+ Stored XSS
- CVE-2021-244401 PoCSign-up Sheets < 1.0.14 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-244411 PoCSign-up Sheets < 1.0.14 - Authenticated CSV Injection
- CVE-2021-244422 PoCsPoll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL Injection
- CVE-2021-244431 PoCYouzify < 1.0.7 - Stored Cross-Site Scripting via Biography
- CVE-2021-244442 PoCsTaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-244451 PoCMy Site Audit <= 1.2.4 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-244461 PoCRemove Footer Credit < 1.0.6 - CSRF to Stored Cross-Site Scripting
- CVE-2021-244471 PoCWP Image Zoom < 1.47 - Local File Inclusion
- CVE-2021-244481 PoCProfile Builder < 3.4.8 - Authenticated Stored XSS
- CVE-2021-244501 PoCProfilePress < 3.1.8 - Authenticated Stored XSS
- CVE-2021-244511 PoCExport Users With Meta < 0.6.5 - Authenticated SQL Injection
- CVE-2021-244522 PoCsW3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)
- CVE-2021-244531 PoCInclude Me <= 1.2.1 - Authenticated Remote Code Execution (RCE) via LFI log poisoning
- CVE-2021-244541 PoCYOP Poll < 6.2.8 - Stored Cross-Site Scripting
- CVE-2021-244551 PoCTutor LMS < 1.9.2 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-244571 PoCPortfolio Responsive Gallery < 1.1.8 - Authenticated Blind SQL Injections
- CVE-2021-244581 PoCPopup box < 2.3.4 - Authenticated Blind SQL Injections
- CVE-2021-244591 PoCSurvey Maker < 1.5.6 - Authenticated Blind SQL Injections
- CVE-2021-244601 PoCPopup Like box - Page Plugin < 3.5.3 - Authenticated Blind SQL Injections
- CVE-2021-244611 PoCFAQ Builder < 1.3.6 - Authenticated Blind SQL Injections
- CVE-2021-244621 PoCPhoto Gallery by Ays - Responsive Image Gallery < 4.4.4 - Authenticated Blind SQL Injections
- CVE-2021-244631 PoCImage Slider by Ays - Responsive Slider and Carousel < 2.5.0 - Authenticated Blind SQL Injection
- CVE-2021-244641 PoCYouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSS
- CVE-2021-244651 PoCMeow Gallery < 4.1.9 - Contributor+ SQL Injection
- CVE-2021-244661 PoCVerse-O-Matic <= 4.1.1 - CSRF to Stored XSS
- CVE-2021-244671 PoCLeaflet Map < 3.0.0 - Arbitrary Settings Update via CSRF Leading to Stored XSS
- CVE-2021-244681 PoCLeaflet Map < 3.0.0 - Contributor+ Stored XSS
- CVE-2021-244711 PoCYouTube Embed < 5.2.2 - Contributor+ Stored XSS
- CVE-2021-244722 PoCsOnair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Unauthenticated RFI and SSRF
- CVE-2021-244731 PoCUser Profile Picture < 2.6.0 - Arbitrary User Picture Change/Deletion via IDOR
- CVE-2021-244761 PoCSteam Group Viewer <= 2.1 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-244771 PoCMigrate Users <= 1.0.1 - CSRF to Stored Cross-Site Scripting (XSS)
- CVE-2021-244781 PoCBookshelf <= 2.0.4 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-244791 PoCDrawBlog <= 0.90 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-244801 PoCEvent Geek <= 2.5.2 - Stored Cross-site Scripting (XSS)
- CVE-2021-244811 PoCAny Hostname <= 1.0.6 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-244821 PoCRelated Posts for WordPress <= 2.0.4 - Authenticated Stored XSS & XFS
- CVE-2021-244831 PoCPoll Maker < 3.2.1 - Authenticated Blind SQL Injections
- CVE-2021-244841 PoCSecure Copy Content Protection and Content Locking < 2.6.7 - Authenticated Blind SQL Injections
- CVE-2021-244851 PoCSpecial Text Boxes < 5.9.110 - Admin+ Stored Cross-Site Scripting
- CVE-2021-244861 PoCSimple Social Media Share Buttons < 3.2.3 - Contributor+ Stored XSS
- CVE-2021-244871 PoCSt Daily Tip <= 4.7 - CSRF to Stored Cross-Site Scripting
- CVE-2021-244883 PoCsPost Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-244891 PoCRequest a Quote < 2.3.9 - Admin+ Stored Cross-Site Scripting
- CVE-2021-244901 PoCEmail Artillery <= 4.1 - Arbitrary File Upload
- CVE-2021-244911 PoCFileviewer <= 2.2 - Arbitrary File Upload/Deletion via CSRF
- CVE-2021-244922 PoCsHandsome Testimonials & Reviews < 2.1.1 - Authenticated (Subscriber+) SQL Injection
- CVE-2021-244931 PoCShopp eCommerce <= 1.4 - Unauthenticated Arbitrary File Upload
- CVE-2021-244941 PoCWP Offload SES Lite < 1.4.5 - Stored Cross-Site Scripting (XSS)
- CVE-2021-244952 PoCsMarmoset Viewer < 1.9.3 - Reflected Cross Site Scripting
- CVE-2021-244961 PoCCommunity Event < 1.4.8 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-244971 PoCGiveaway <= 1.2.2 - Authenticated SQL Injection
- CVE-2021-244982 PoCsCalendar Event Multi View < 1.4.01 - Unauthenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-2449910 PoCsWorkreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
- CVE-2021-245002 PoCsWorkreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities
- CVE-2021-245012 PoCsWorkreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions
- CVE-2021-245022 PoCsWP Google Map < 1.7.7 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245031 PoCPopular Brand SVG Icons - Simple Icons < 2.7.8 - Contributor+ Stored XSS
- CVE-2021-245041 PoCWP LMS <= 1.1.2 - Stored Cross-Site Scripting (XSS)
- CVE-2021-245051 PoCForms < 1.12.3 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245061 PoCSlider Hero < 8.2.7 - Contributor+ SQL Injection
- CVE-2021-245072 PoCsAstra Pro Addon < 3.5.2 - Unauthenticated SQL Injection
- CVE-2021-245081 PoCSmash Balloon Social Post Feed < 2.19.2 - Unauthenticated Stored XSS
- CVE-2021-245091 PoCPage View Counts < 2.4.9 - Contributor+ Stored XSS
- CVE-2021-245102 PoCsMF Gig Calendar < 1.2 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-245112 PoCsCreate WooCommerce Product Feeds For 40+ Merchants < 3.3.1.0 - Authenticated SQL Injection
- CVE-2021-245121 PoCVideo Posts Webcam Recorder < 3.2.4 - Authenticated Reflected XSS
- CVE-2021-245131 PoCForm Builder < 1.9.8.4 - Authenticated Stored Cross-Site Scripting
- CVE-2021-245141 PoCVisual Form Builder < 3.0.4 - Admin+ Stored Cross-Site Scripting
- CVE-2021-245151 PoCVideo Gallery - Vimeo and YouTube Gallery < 1.1.5 - Admin+ Stored Cross-Site Scripting
- CVE-2021-245161 PoCPlanSo Forms <= 2.6.3 - Authenticated Stored Cross-Site Scripting
- CVE-2021-245171 PoCStop Spammers Security < 2021.18 - Authenticated Stored XSS
- CVE-2021-245182 PoCsWPFront Notification Bar < 2.0.0.07176 - Authenticated Stored XSS
- CVE-2021-245191 PoCVik Rent Car < 1.1.10 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245201 PoCStock in & out <= 1.0.4 - Authenticated SQL Injection
- CVE-2021-245212 PoCsSide Menu Lite < 2.2.1 - Authenticated SQL Injection
- CVE-2021-245222 PoCsProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widget
- CVE-2021-245231 PoCDaily Prayer Time < 2021.08.10 - Authenticated Stored XSS
- CVE-2021-245241 PoCGiveWP < 2.12.0 - Authenticated Stored XSS
- CVE-2021-245251 PoCShortcodes Ultimate < 5.10.2 - Contributor+ Stored XSS
- CVE-2021-245261 PoCForm Maker < 1.13.60 - Authenticated Stored XSS
- CVE-2021-245272 PoCsProfile Builder < 3.4.9 - Admin Access via Password Reset
- CVE-2021-245281 PoCFluentSMTP < 2.0.1 - Authenticated Stored XSS
- CVE-2021-245291 PoCGrid Gallery < 1.2.5 - Authenticated Stored Cross Site Scripting (XSS)
- CVE-2021-245301 PoCAlojapro Widget <= 1.1.15 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245331 PoCMaintenance < 4.03 - Authenticated Stored XSS
- CVE-2021-245341 PoCPhoneTrack Meu Site Manager <= 0.1 - Authenticated Stored XSS
- CVE-2021-245351 PoCLight Messages <= 1.0 - CSRF to Stored XSS
- CVE-2021-245361 PoCCustom Login Redirect <= 1.0.0 - CSRF to Stored XSS
- CVE-2021-245371 PoCSimilar Posts <= 3.1.5 - Admin+ Arbitrary PHP Code Execution
- CVE-2021-245381 PoCCurrent Book <= 1.0.1 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245391 PoCComing Soon, Under Construction & Maintenance Mode By Dazzler < 1.6.7 - Admin+ Stored Cross-Site Scripting
- CVE-2021-245401 PoCWonder Video Embed < 1.8 - Contributor+ Stored XSS
- CVE-2021-245411 PoCWonder PDF Embed < 1.7 - Contributor+ Stored XSS
- CVE-2021-245431 PoCjQuery Reply to Comment <= 1.31 - CSRF to Stored Cross-Site Scripting
- CVE-2021-245441 PoCResponsive WordPress Slider <= 2.2.0 - Subscriber+ Stored Cross-Site Scripting
- CVE-2021-245453 PoCsWP HTML Author Bio <= 1.2.0 - Author+ Stored Cross-Site Scripting
- CVE-2021-245461 PoCEditorsKit < 1.31.6 - Contributor+ Arbitrary PHP Code Execution
- CVE-2021-245471 PoCKN Fix Your Title <= 1.0.1 - Authenticated Stored XSS
- CVE-2021-245481 PoCMimetic Books <= 0.2.13 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245492 PoCsAceIDE <= 2.6.2 - Authenticated (admin+) Arbitrary File Access
- CVE-2021-245502 PoCsBroken Link Manager <= 0.6.5 - Authenticated (admin+) SQL Injection
- CVE-2021-245512 PoCsEdit Comments <= 0.3 - Unauthenticated SQL Injection
- CVE-2021-245522 PoCsSimple Events Calendar <= 1.4.0 - Authenticated (admin+) SQL Injection
- CVE-2021-245532 PoCsTimeline Calendar <= 1.2 - Authenticated (admin+) SQL Injection
- CVE-2021-245543 PoCsPaytm - Donation Plugin <= 1.3.2 - Authenticated (admin+) SQL Injection
- CVE-2021-245552 PoCsDiary & Availability Calendar <= 1.0.3 - Authenticated (subscriber+) SQL Injection
- CVE-2021-245562 PoCsEmail Subscriber <= 1.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245572 PoCsM-vSlider <= 2.1.3 - Authenticated (admin+) SQL Injection
- CVE-2021-245582 PoCsProject Status <= 1.6 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-245591 PoCQyrr < 0.7 - Authenticated (contributor+) Stored XSS
- CVE-2021-245611 PoCWP SMS < 5.4.13 - Authenticated Stored Cross-Site Scripting
- CVE-2021-245621 PoCLifterLMS < 4.21.2 - Access Other Student Grades/Answers via IDOR
- CVE-2021-245634 PoCsFrontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-245641 PoCWPFront Scroll Top < 2.0.6.07225 - Authenticated Stored XSS
- CVE-2021-245651 PoCContact Form 7 Captcha < 0.0.9 - CSRF to Stored XSS
- CVE-2021-245662 PoCsWooCommerce Currency Switcher < 1.3.7 - Authenticated (Low Privilege) Local File Inclusion
- CVE-2021-245671 PoCSimple Post <= 1.1 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245681 PoCAddToAny < 1.7.46 - Authenticated Stored XSS
- CVE-2021-245691 PoCCookie Notice & Compliance for GDPR / CCPA < 2.1.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-245701 PoCPaypal Donation < 1.3.1 - CSRF to Stored Cross-Site Scripting
- CVE-2021-245711 PoCHD Quiz < 1.8.4 - Authenticated Stored XSS
- CVE-2021-245721 PoCPaypal Donation < 1.3.1 - CSRF to Arbitrary Post Deletion
- CVE-2021-245741 PoCSimple Banner < 2.10.4 - Authenticated Stored XSS
- CVE-2021-245751 PoCWPSchoolPress < 2.1.10 - Multiple Authenticated SQL Injections
- CVE-2021-245761 PoCEasy Accordion < 2.0.22 - Authenticated Stored XSS
- CVE-2021-245771 PoCComing Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSS
- CVE-2021-245781 PoCSportsPress < 2.7.9 - Reflected Cross-Site Scripting
- CVE-2021-245791 PoCBold Page Builder < 3.1.6 - PHP Object Injection
- CVE-2021-245801 PoCSide Menu Lite < 2.2.6 - Authenticated SQL Injection
- CVE-2021-245812 PoCsBlue Admin <= 21.06.01 - CSRF to Stored Cross-Site Scripting (XSS)
- CVE-2021-245821 PoCThinkTwit < 1.7.1 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245831 PoCTimetable and Event Schedule by MotoPress < 2.4.2 - Unauthorised Event TimeSlot Deletion
- CVE-2021-245841 PoCTimetable and Event Schedule by MotoPress < 2.4.2 - Unauthorised Event TimeSlot Update
- CVE-2021-245851 PoCTimetable and Event Schedule by MotoPress < 2.4.0 - Arbitrary User's Hashed Password/Email/Username Disclosure
- CVE-2021-245861 PoCPer Page Add to Head < 1.4.4 - CSRF to Stored XSS
- CVE-2021-245871 PoCSplash Header < 1.20.8 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-245881 PoCSMS Alert Order Notifications – WooCommerce < 3.4.7 Authenticated Cross Site Scripting
- CVE-2021-245901 PoCCookie Notice & Consent Banner for GDPR & CCPA Compliance < 1.7.2 - Authenticated Stored XSS
- CVE-2021-245911 PoCHighlight < 0.9.3 - Authenticated Stored Cross-Site Scripting
- CVE-2021-245921 PoCSitewide Notice WP < 2.3 - Authenticated Stored XSS
- CVE-2021-245931 PoCBusiness Hours Indicator < 2.3.5 - Authenticated Stored XSS
- CVE-2021-245941 PoCTranslate WordPress - Google Language Translator < 6.0.12 - Admin+ Stored Cross-Site Scripting
- CVE-2021-245961 PoCyouForms for WordPress <= 1.0.5 - Authenticated Stored Cross-Site Scripting
- CVE-2021-245971 PoCYou Shang <= 1.0.1 - Authenticated Stored Cross-Site Scripting
- CVE-2021-245981 PoCTestimonial Builder < 1.6.0 - Admin+ Stored Cross-Site Scripting
- CVE-2021-245991 PoCEmail Encoder < 2.1.2 - Reflected Cross Site Scripting
- CVE-2021-246001 PoCWP Dialog <= 1.2.5.5 - Authenticated Stored Cross-Site Scripting
- CVE-2021-246011 PoCWPFront Notification Bar < 2.1.0.08087 - Authenticated Stored XSS
- CVE-2021-246031 PoCSite Reviews < 5.13.1 - Authenticated Stored XSS
- CVE-2021-246041 PoCAvailability Calendar < 1.2.2 - Authenticated Stored Cross-Site Scripting
- CVE-2021-246051 PoCCustom Post View Generator <= 0.4.6 - Reflected Cross-Site Scripting
- CVE-2021-246061 PoCAvailability Calendar < 1.2.1 - Authenticated SQL Injection
- CVE-2021-246071 PoCStorefront Footer Text <= 1.0.1 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246081 PoCFormidable Form Builder < 5.0.07 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246091 PoCWP Mapa Politico Espana < 3.7.0- Authenticated Stored XSS
- CVE-2021-246103 PoCsTranslatePress < 2.0.9 - Authenticated Stored Cross-Site Scripting
- CVE-2021-246111 PoCKeywords & Meta <= 3.0 - CSRF to Stored Cross-Site Scripting (XSS)
- CVE-2021-246121 PoCSociable <= 4.3.4.1 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246131 PoCPost Views Counter < 1.3.5 - Authenticated Stored XSS
- CVE-2021-246141 PoCBook appointment Online < 1.39 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-246161 PoCAddToAny Share Buttons < 1.7.48 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246181 PoCDonate With QRCode < 1.4.5 - Stored Cross-Site Scripting
- CVE-2021-246191 PoCPer Page Add to Head <= 1.4.4 - Authenticated Stored XSS
- CVE-2021-246201 PoCSimple eCommerce <= 2.2.5 - Arbitrary File Upload
- CVE-2021-246211 PoCWP Courses LMS < 2.0.44 - Authenticated Stored XSS via Video Embed Code
- CVE-2021-246221 PoCWP Ticket < 5.10.4 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246231 PoCWordPress Advanced Ticket System < 1.0.64 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-246241 PoCMP3 Audio Player for Music, Radio & Podcast by Sonaar < 2.4.2 - Multiple Admin+ Cross Site Scripting
- CVE-2021-246252 PoCsSpiderCatalog <= 1.7.3 - Admin+ SQL Injection
- CVE-2021-246262 PoCsChameleon CSS <= 1.2 - Subscriber+ SQL Injection
- CVE-2021-246273 PoCsG Auto-Hyperlink <= 1.0.1 - Admin+ SQL Injection
- CVE-2021-246282 PoCsWow Forms <= 3.1.3 - Admin+ SQL Injection
- CVE-2021-246292 PoCsPost Content XMLRPC <= 1.0 - Admin+ SQL Injections
- CVE-2021-246302 PoCsSchreikasten <= 0.14.18 - Author+ SQL Injections
- CVE-2021-246312 PoCsUnlimited PopUps <= 4.5.3 - Author+ SQL Injection
- CVE-2021-246321 PoCRecipe Card Blocks < 2.8.1 - Reflected Cross-Site Scripting
- CVE-2021-246331 PoCCountdown Block < 1.1.2 - Missing Authorisation in AJAX action
- CVE-2021-246341 PoCRecipe Card Blocks < 2.8.3 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-246351 PoCVisual Link Preview < 2.2.3 - Unauthorised AJAX Calls
- CVE-2021-246361 PoCPrint My Blog < 3.4.2 - Plugin Deactivation via CSRF
- CVE-2021-246371 PoCFonts Plugin < 3.0.3 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-246381 PoCOMGF < 4.5.4 - Unauthenticated Path Traversal in REST API
- CVE-2021-246391 PoCOMGF < 4.5.4 - Subscriber+ Arbitrary File/Folder Deletion
- CVE-2021-246401 PoCGutenslider < 5.2.0 - Contributor+ Stored XSS
- CVE-2021-246411 PoCImages to WebP < 1.9 - Multiple Cross Site Request Forgery (CSRF)
- CVE-2021-246421 PoCScroll Baner <= 1.0 - CSRF to RCE
- CVE-2021-246431 PoCWP Map Block < 1.2.3 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-246442 PoCsImages to WebP < 1.9 - Authenticated Local File Inclusion
- CVE-2021-246451 PoCBooking.com Product Helper < 1.0.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246461 PoCBooking.com Banner Creator < 1.4.3 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246473 PoCsPie Register < 3.7.1.6 - Unauthenticated Arbitrary Login
- CVE-2021-246481 PoCRegistration Magic < 5.0.1.9 - Reflected Cross-Site Scripting
- CVE-2021-246491 PoCWP User Frontend < 3.5.29 - Obscure Registration as Admin
- CVE-2021-246511 PoCPoll Maker < 3.4.2 - Unauthenticated Time Based SQL Injection
- CVE-2021-246531 PoCCookie Bar < 1.8.9 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246541 PoCUser Registration < 2.0.2 - Low Privilege Stored Cross-Site Scripting
- CVE-2021-246551 PoCWP User Manager < 2.6.3 - Arbitrary User Password Reset to Account Compromise
- CVE-2021-246561 PoCSimple Social Media Share Buttons < 3.2.4 - Authenticated Stored Cross-Site Scripting
- CVE-2021-246572 PoCsLimit Login Attempts < 4.0.50 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-246581 PoCErident Custom Login and Dashboard < 3.5.9 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-246621 PoCGame Server Status <= 1.0 - Admin+ SQL Injection
- CVE-2021-246631 PoCSimple School Staff Directory <= 1.1 - Admin+ Arbitrary File Upload
- CVE-2021-246642 PoCsWPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
- CVE-2021-246662 PoCsPodlove Podcast Publisher < 3.5.6 - Unauthenticated SQL Injection
- CVE-2021-246681 PoCMAZ Loader < 1.4.1 - Arbitrary Loader Deletion via CSRF
- CVE-2021-246691 PoCMAZ Loader < 1.3.3 - Contributor+ SQL Injection
- CVE-2021-246701 PoCCoolClock < 4.3.5 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-246711 PoCMX Time Zone Clocks < 3.4.1 - Contributor+ Cross-Site Scripting
- CVE-2021-246721 PoCOne User Avatar < 2.3.7 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-246731 PoCAppointment Hour Booking < 1.3.16 - Authenticated Stored Cross-Site Scripting
- CVE-2021-246741 PoCGenie WP Favicon <= 0.5.2 - Arbitrary Favicon Change via CSRF
- CVE-2021-246751 PoCOne User Avatar < 2.3.7 - Avatar Update via CSRF
- CVE-2021-246761 PoCBetter Find and Replace < 1.2.9 - Reflected Cross-Site Scripting
- CVE-2021-246771 PoCFind My Blocks < 3.4.0 - Private Post Titles Disclosure
- CVE-2021-246781 PoCCM Tooltip Glossary < 3.9.21 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-246791 PoCBitcoin / AltCoin Payment Gateway for WooCommerce < 1.6.1 - Reflected Cross-Site Scripting
- CVE-2021-246801 PoCWP Travel Engine < 5.3.1 - Editor+ Stored Cross-Site Scripting
- CVE-2021-246812 PoCsDuplicate Page <= 4.4.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246821 PoCCool Tag Cloud < 2.26 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-246831 PoCWeather Effect < 1.3.4 - CSRF to Stored Cross-Site Scripting
- CVE-2021-246841 PoCPDF Light Viewer < 1.4.12 - Authenticated Command Injection
- CVE-2021-246851 PoCFlat Preloader < 1.5.4 - CSRF to Stored Cross-Site Scripting
- CVE-2021-246861 PoCSVG Support < 2.3.20 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246871 PoCModern Events Calendar Lite < 5.22.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246881 PoCOrange Form <= 1.0.1 - Unauthenticated Arbitrary Post Deletion
- CVE-2021-246891 PoCContact Forms - Drag & Drop Contact Form Builder <= 1.0.5 - Admin+ Arbitrary System File Read
- CVE-2021-246901 PoCChained Quiz < 1.2.7.2 - Authenticated Stored Cross Site Scripting
- CVE-2021-246911 PoCQuiz And Survey Master < 7.3.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-246921 PoCSimple Download Monitor < 3.9.5 - Contributor+ Arbitrary File Download via Path Traversal
- CVE-2021-246931 PoCSimple Download Monitor < 3.9.5 - Contributor+ Stored Cross-Site Scripting via File Thumbnail
- CVE-2021-246941 PoCSimple Download Monitor < 3.9.11 - Contributor+ Stored Cross-Site Scripting via Shortcodes
- CVE-2021-246951 PoCSimple Download Monitor < 3.9.6 - Unauthenticated Log Access
- CVE-2021-246961 PoCSimple Download Monitor < 3.9.9 - Multiple CSRF
- CVE-2021-246971 PoCSimple Download Monitor < 3.9.5 - Reflected Cross-Site Scripting
- CVE-2021-246981 PoCSimple Download Monitor < 3.9.6 - Arbitrary Thumbnails Removal
- CVE-2021-246991 PoCEasy Media Download < 1.1.7 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-247001 PoCForminator < 1.15.4 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247011 PoCQuiz Tool Lite <= 2.3.15 - Multiple Admin+ Stored Cross-Site Scripting
- CVE-2021-247021 PoCLearnPress < 4.1.3.1 - Multiple Admin+ Stored Cross-Site Scripting
- CVE-2021-247031 PoCDownload Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin Activation
- CVE-2021-247041 PoCOrange Form <= 1.0 - SQL Injection via CSRF
- CVE-2021-247051 PoCNEX-Forms < 8.4.3 - Stored Cross-Site Scripting via CSRF
- CVE-2021-247061 PoCQwizcards < 3.62 - Admin+ Stored Cross Site Scripting
- CVE-2021-247071 PoCLearning Courses < 5.0 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247081 PoCWP All Export < 1.3.1 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247091 PoCWeather Effect < 1.3.6 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247101 PoCPrint-O-Matic < 2.0.3 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247111 PoCSoftware License Manager < 4.5.1 - Arbitrary Domain Deletion via CSRF
- CVE-2021-247121 PoCAppointment Hour Booking – WordPress Booking Plugin < 1.3.17 - Authenticated Stored XSS
- CVE-2021-247131 PoCVideo Lessons Manager - Admin+ Stored Cross-Site Scripting
- CVE-2021-247141 PoCWP All Import < 3.6.3 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247151 PoCWP Sitemap Page < 1.7.0 - Admin+ Stored Cross Site Scripting
- CVE-2021-247161 PoCModern Events Calendar Lite < 5.22.3 - Authenticated Stored Cross Site Scripting
- CVE-2021-247171 PoCAutomatorWP < 1.7.6 - Missing Authorization and Privilege Escalation
- CVE-2021-247181 PoCARForms Form Builder < 1.5 - Admin+ Stored Cross Site Scripting
- CVE-2021-247193 PoCsEnfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-247201 PoCGeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-247211 PoCLoco Translate < 2.5.4 - Authenticated PHP Code Injection
- CVE-2021-247221 PoCRestaurant Menu by MotoPress < 2.4.2 - Admin+ Stored Cross Site Scripting
- CVE-2021-247231 PoCWP Reactions Lite < 1.3.6 - Authenticated Stored Cross Site Scripting
- CVE-2021-247242 PoCsTimetable and Event Schedule by MotoPress < 2.3.19 - Author+ Stored Cross-Site Scripting
- CVE-2021-247252 PoCsComment Link Remove and Other Comment Tools < 2.1.6 - Arbitrary Comment Deletion via CSRF
- CVE-2021-247262 PoCsWP Simple Booking Calendar <= 2.0.6 (before 07/12/2021) - Authenticated SQL Injection
- CVE-2021-247272 PoCsBlock and Stop Bad Bots < 6.60 - Authenticated SQL Injections
- CVE-2021-247282 PoCsPaid Member Subscriptions < 2.4.2 - Authenticated SQL Injection
- CVE-2021-247291 PoCLogo Showcase with Slick Slider < 1.2.4 - Author+ Stored Cross Site Scripting
- CVE-2021-247301 PoCLogo Showcase with Slick Slider < 1.2.5 - Subscriber+ Arbitrary Media Title/Description/Alt Text/URL Update
- CVE-2021-247312 PoCsPie Register < 3.7.1.6 - Unauthenticated SQL Injection
- CVE-2021-247321 PoCDflip Lite < 1.7.10 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-247331 PoCWP Post Page Clone < 1.2 - Unauthorised Post Access
- CVE-2021-247341 PoCCompact WP Audio Player < 1.9.7 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-247351 PoCCompact WP Audio Player < 1.9.7 - Setting Change via CSRF
- CVE-2021-247361 PoCShared Files < 1.6.57 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247371 PoCComments - wpDiscuz <= 7.3.0 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247381 PoCLogo Carousel < 3.4.2 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-247391 PoCLogo Carousel < 3.4.2 - Unauthorised Private Post Access
- CVE-2021-247401 PoCTutor LMS < 1.9.9 - Multiple Admin+ Stored Cross-Site Scripting
- CVE-2021-247413 PoCsSupport Board < 3.3.4 - Multiple Unauthenticated SQL Injections
- CVE-2021-247421 PoCLogo Slider and Showcase < 1.3.37 - Editor Plugin's Settings Update
- CVE-2021-247431 PoCPodcast Subscribe Buttons < 1.4.2 - Contributor+ Stored XSS
- CVE-2021-247441 PoCWordPress Contact Forms by Cimatti < 1.4.12 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247451 PoCAbout Author Box < 1.0.2 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-247462 PoCsSassy Social Share < 3.3.40 - Reflected Cross-Site Scripting
- CVE-2021-247471 PoCSEO Booster < 3.8 - Admin+ SQL Injection
- CVE-2021-247481 PoCEmail Before Download < 6.8 - Admin+ SQL Injection
- CVE-2021-247491 PoCURL Shortify < 1.5.1 - Arbitrary Link/Group Deletion via CSRF
- CVE-2021-247505 PoCsWP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
- CVE-2021-247511 PoCGenerateBlocks < 1.4.0 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-247521 PoCMultiple Plugins from CatchThemes - Unauthorised Plugin's Setting Change
- CVE-2021-247531 PoCRich Reviews by Starfish < 1.9.6 - Admin+ SQL Injection
- CVE-2021-247541 PoCMainWP Child Reports < 2.0.8 - Admin+ SQL Injection
- CVE-2021-247551 PoCmyCred < 2.3 - Subscriber+ SQL Injection
- CVE-2021-247561 PoCWP System Log < 1.0.21 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-247571 PoCStylish Price List < 6.9.0 - Unauthenticated Arbitrary Image Upload
- CVE-2021-247581 PoCEmail Log < 2.4.7 - Admin+ SQL Injection
- CVE-2021-247591 PoCPDF.js Viewer < 2.0.2 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-247601 PoCGutenberg PDF Viewer Block < 1.0.1 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-247611 PoCError Log Viewer < 1.1.2 - Arbitrary Text File Deletion via CSRF
- CVE-2021-247626 PoCsPerfect Survey < 1.5.2 - Unauthenticated SQL Injection
- CVE-2021-247631 PoCPerfect Survey < 1.5.2 - Unauthorised AJAX Call to Stored XSS / Survey Settings Update
- CVE-2021-247641 PoCPerfect Survey < 1.5.2 - Reflected Cross-Site Scripting
- CVE-2021-247651 PoCPerfect Survey < 1.5.2 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-247661 PoC404 to 301 < 3.0.9 - Logs Deletion via CSRF
- CVE-2021-247671 PoCRedirect 404 Error Page to Homepage or Custom Page with Logs < 1.7.9 - Log Deletion via CSRF
- CVE-2021-247681 PoCWP RSS Aggregator < 4.19.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247691 PoCPermalink Manager Lite < 2.2.13.1 - Admin+ SQL Injection
- CVE-2021-247701 PoCStylish Price List < 6.9.1 - Subscriber+ Arbitrary Image Upload
- CVE-2021-247711 PoCInspirational Quote Rotator <= 1.0.0 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247721 PoCStream < 3.8.2 - Admin+ SQL Injection
- CVE-2021-247731 PoCWordPress Download Manager < 3.2.16 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247741 PoCCheck & Log Email < 1.0.3 - Admin+ SQL Injections
- CVE-2021-247751 PoCDocument Embedder < 1.7.5 - Unauthenticated Arbitrary Private/Draft Post Title Disclosure
- CVE-2021-247761 PoCWP Performance Score Booster < 2.1 - Settings Change via CSRF
- CVE-2021-247771 PoCHotscot Contact Form < 1.3 - Admin+ SQL Injection
- CVE-2021-247781 PoCTradetracker-Store < 4.6.60 - Admin+ SQL Injection
- CVE-2021-247791 PoCWP Debugging < 2.11.0 - Unauthenticated Plugin's Settings Update
- CVE-2021-247801 PoCSingle Post Exporter <= 1.1.1 - Plugin's Settings Update via CSRF
- CVE-2021-247811 PoCImage Source Control < 2.3.1 - Contributor+ Arbitrary Post Meta Value Change
- CVE-2021-247821 PoCFlex Local Fonts <= 1.0.0 - Admin+ Stored Cross-Site-Scripting
- CVE-2021-247831 PoCPost Expirator < 2.6.0 - Contributor+ Arbitrary Post Schedule Deletion
- CVE-2021-247841 PoCWP Admin Logo Changer <= 1.0 - Plugin's Settings Update via CSRF
- CVE-2021-247851 PoCGreat Quotes <= 1.0.0 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247863 PoCsDownload Monitor < 4.4.5 - Admin+ SQL Injection
- CVE-2021-247871 PoCClient Invoicing by Sprout Invoices < 19.9.7 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247881 PoCBatch Cat <= 0.3 - Subscriber+ Arbitrary Categories Add/Set/Delete to Posts
- CVE-2021-247891 PoCFlat Preloader < 1.5.5 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247901 PoCContact Form Advanced Database <= 1.0.8 - Unauthorised AJAX Calls
- CVE-2021-247912 PoCsHeader Footer Code Manager < 1.1.14 - Admin+ SQL Injections
- CVE-2021-247921 PoCShiny Buttons <= 1.1.0 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-247931 PoCWPeMatico RSS Feed Fetcher < 2.6.12 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247941 PoCConnections Business Directory < 10.4.3 - Admin+ Stored Cross-Site Scripting
- CVE-2021-247951 PoCFilter Portfolio Gallery <= 1.5 - Arbitrary Gallery Deletion via CSRF
- CVE-2021-247961 PoCMy Tickets < 1.8.31 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-247971 PoCTickera < 3.4.8.3 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-247981 PoCWP Header Images < 2.0.1 - Reflected Cross-Site Scripting
- CVE-2021-247991 PoCFar Future Expiry Header < 1.5 - Plugin's Settings Update via CSRF
- CVE-2021-248001 PoCDW Question & Answer Pro <= 1.3.4 - Arbitrary Comment Edition via IDOR
- CVE-2021-248011 PoCWP Survey Plus <= 1.0 - Subscriber+ AJAX Calls
- CVE-2021-248021 PoCColorful Categories < 2.0.15 - Arbitrary Colors Update via CSRF
- CVE-2021-248031 PoCCore Tweaks WP Setup <= 4.1 - Arbitrary Admin Account Creation / Admin Email Update via CSRF
- CVE-2021-248041 PoCSimple JWT Login < 3.2.1 - Arbitrary Settings Update to Site Takeover via CSRF
- CVE-2021-248051 PoCDW Question & Answer Pro <= 1.3.4 - Multiple CSRF
- CVE-2021-248061 PoCwpDiscuz < 7.3.4 - Arbitrary Comment Addition/Edition/Deletion via CSRF
- CVE-2021-248073 PoCsSupport Board < 3.3.5 - Agent+ Stored Cross-Site Scripting
- CVE-2021-248081 PoCBP Better Messages < 1.9.9.41 - Reflected Cross-Site Scripting
- CVE-2021-248091 PoCBP Better Messages < 1.9.9.41 - Multiple CSRF
- CVE-2021-248101 PoCWP Event Manager < 3.1.23 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248111 PoCShop Page WP < 1.2.8 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248121 PoCBetterLinks < 1.2.6 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248131 PoCEvents Made Easy < 2.2.24 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248141 PoCWordPress GDPR & CCPA < 1.9.26 - Authenticated Reflected Cross-Site Scripting
- CVE-2021-248151 PoCPaypal Donation < 1.3.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248161 PoCPhoenix Media Rename < 3.4.4 - Author Arbitrary Media File Renaming
- CVE-2021-248171 PoCUltimate NoFollow <= 1.4.8 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248181 PoCWP Limits <= 1.0 - Plugin's Settings Update via CSRF
- CVE-2021-248191 PoCPage/Post Content Shortcode <= 1.0 - Contributor+ Arbitrary Posts/Pages Access
- CVE-2021-248211 PoCCost Calculator < 1.6 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248221 PoCStylish Cost Calculator < 7.04 - Subscriber+ Unauthorised AJAX Calls to Stored XSS
- CVE-2021-248232 PoCsSupport Board < 3.3.6 - Arbitrary File Deletion via CSRF
- CVE-2021-248241 PoCCustom Content Shortcode < 4.0.1 - Unauthorised Arbitrary Post Metadata Access
- CVE-2021-248251 PoCCustom Content Shortcode < 4.0.2 - Authenticated Arbitrary File Access / LFI
- CVE-2021-248261 PoCCustom Content Shortcode < 4.0.2 - Authenticated Stored Cross-Site Scripting
- CVE-2021-248272 PoCsAsgaros Forum < 1.15.13 - Unauthenticated SQL Injection
- CVE-2021-248281 PoCMortgage Calculator / Loan Calculator < 1.5.17 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248291 PoCVisitor Traffic Real Time Statistics < 3.9 - Subscriber+ SQL Injection
- CVE-2021-248301 PoCAdvanced Access Manager < 6.8.0 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248311 PoCTab - Accordion, FAQ < 1.3.2 - Unauthenticated AJAX Calls
- CVE-2021-248321 PoCWP SEO Redirect 301 < 2.3.2 - Redirect Deletion via CSRF
- CVE-2021-248351 PoCWCFM - Frontend Manager for WooCommerce < 6.5.12 - Customer/Subscriber+ SQL Injection
- CVE-2021-248361 PoCTemporary Login Without Password < 1.7.1 - Subscriber+ Plugin's Settings Update
- CVE-2021-248371 PoCPassster < 3.5.5.8 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248382 PoCsAnyComment < 0.3.5 - Open Redirect
- CVE-2021-248391 PoCSupportCandy < 2.2.5 - Unauthenticated Arbitrary Ticket Deletion
- CVE-2021-248401 PoCSquaretype Modern Blog < 3.0.4 - Unauthenticated Private/Schedule Posts Disclosure
- CVE-2021-248412 PoCsHelpful < 4.4.59 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248421 PoCBulk Datetime Change < 1.12 - Missing Authorisation
- CVE-2021-248431 PoCSupportCandy < 2.2.7 - Arbitrary Ticket Deletion via CSRF
- CVE-2021-248441 PoCAffiliate Manager < 2.8.7 - Admin+ SQL injection
- CVE-2021-248451 PoCImproved Include Page <= 1.2 - Contributor+ Arbitrary Posts/Pages Access
- CVE-2021-248461 PoCNi WooCommerce Custom Order Status < 1.9.7 - Subscriber+ SQL Injection
- CVE-2021-248471 PoCSEO Redirection < 8.2 - Subscriber+ SQL Injection
- CVE-2021-248481 PoCMediamatic < 2.8.1 - Subscriber+ SQL Injection
- CVE-2021-248492 PoCsWCFM - WooCommerce Multivendor Marketplace < 3.4.12 - Unauthenticated SQL Injection
- CVE-2021-248501 PoCInsert Pages < 3.7.0 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248511 PoCInsert Pages < 3.7.0 - Contributor+ Arbitrary Posts/Pages Access
- CVE-2021-248521 PoCMouseWheel Smooth Scroll < 5.7 - Plugin's Setting Update via CSRF
- CVE-2021-248531 PoCQR Redirector < 1.6 - Subscriber+ Arbitrary QR Redirect Response Status Update
- CVE-2021-248541 PoCQR Redirector < 1.6.1 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248551 PoCDisplay Post Metadata < 1.5.0 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248561 PoCShared Files < 1.6.61 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248571 PoCToTop Link <= 1.7.1 - Unauthenticated PHP Object Injection
- CVE-2021-248581 PoCWP Cookie User Info < 1.0.9 - Admin+ SQL Injection
- CVE-2021-248591 PoCUser Meta Shortcodes <= 0.5 - Contributor+ Unauthorized Arbitrary User Metadata Access
- CVE-2021-248601 PoCBSK PDF Manager < 3.1.2 - Admin+ SQL Injection
- CVE-2021-248611 PoCQuotes Collection <= 2.5.2 - Admin+ SQL Injection
- CVE-2021-248625 PoCsRegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
- CVE-2021-248631 PoCStopBadBots < 6.67 - Unauthenticated SQL Injection
- CVE-2021-248651 PoCAdvanced Custom Fields: Extended < 0.8.8.7 - Admin+ SQL Injection
- CVE-2021-248661 PoCWP Data Access < 5.0.0 - Admin+ SQL Injection
- CVE-2021-248681 PoCDocument Embedder < 1.7.9 - Subscriber+ Arbitrary Private/Draft Post Title Disclosure
- CVE-2021-248692 PoCsWP Fastest Cache < 0.9.5 - Subscriber+ SQL Injection
- CVE-2021-248702 PoCsWP Fastest Cache < 0.9.5 - CSRF to Stored Cross-Site Scripting
- CVE-2021-248711 PoCGet Custom Field Values < 4.0.1 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248721 PoCGet Custom Field Values < 4.0 - Contributors+ Arbitrary Post Metadata Access
- CVE-2021-248741 PoCNewsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.31 - Reflected Cross-Site Scripting
- CVE-2021-248751 PoCeCommerce Product Catalog for WordPress < 3.0.39 - Reflected Cross-Site Scripting
- CVE-2021-248762 PoCsRegistrations for The Events Calendar < 2.7.5 - Reflected Cross-Site Scripting
- CVE-2021-248771 PoCMainWP Child < 4.1.8 - Admin+ SQL Injection
- CVE-2021-248782 PoCsSupportCandy < 2.2.7 - Reflected Cross-Site Scripting
- CVE-2021-248791 PoCSupportCandy < 2.2.7 - CSRF to Cross-Site Scripting
- CVE-2021-248801 PoCSupportCandy < 2.2.7 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248811 PoCPassster < 3.5.5.9 - Protection Bypass & Arbitrary Post Access
- CVE-2021-248821 PoCSlideshow Gallery < 1.7.4 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248842 PoCsFormidable Form Builder < 4.09.05 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-248851 PoCYOP Poll < 6.1.2 - Reflected Cross-Site Scripting
- CVE-2021-248881 PoCImageBoss < 3.0.6 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248891 PoCNinja Forms < 3.6.4 - Admin+ SQL Injection
- CVE-2021-248901 PoCScripts Organizer < 3.0 - Unauthenticated Arbitrary File Upload
- CVE-2021-248913 PoCsElementor < 3.4.8 - DOM Cross-Site-Scripting
- CVE-2021-248921 PoCAdvanced Forms < 1.6.9 - Subscriber+ Arbitrary User Email Address Update via IDOR
- CVE-2021-248931 PoCStars Rating < 3.5.1 - Comments Denial of Service
- CVE-2021-248941 PoCReviews Plus < 1.2.14 - Subscriber+ Reviews DoS
- CVE-2021-248951 PoCCybersoldier < 1.7.0 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248961 PoCCaldera forms < 1.9.5 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248971 PoCAdd Subtitle <= 1.1.0 - Contributor+ Stored Cross-Site Scripting
- CVE-2021-248981 PoCEditableTable <= 0.1.4 - Admin+ Stored Cross-Site Scripting
- CVE-2021-248991 PoCMedia-Tags <= 3.2.0.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-249002 PoCsNinja Tables < 4.1.8 - Admin+ Stored Cross-Site Cross-Site Scripting
- CVE-2021-249012 PoCsSecurity Audit <= 1.0.0 - Admin+ Stored Cross Site Scripting
- CVE-2021-249021 PoCTypebot < 1.4.3 - Admin+ Stored Cross Site Scripting
- CVE-2021-249031 PoCGRAND FlaGallery <= 6.1.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-249042 PoCsMortgage Calculators WP < 1.56 - Admin+ Stored Cross-Site Scripting
- CVE-2021-249051 PoCAdvanced Contact form 7 DB < 1.8.7 - Subscriber+ Arbitrary File Deletion
- CVE-2021-249061 PoCProtect WP Admin < 3.6.2 - Unauthenticated Plugin Deactivation
- CVE-2021-249071 PoCEverest Forms < 1.8.0 - Reflected Cross-Site Scripting
- CVE-2021-249081 PoCCheck & Log Email < 1.0.4 - Reflected Cross-Site Scripting
- CVE-2021-249091 PoCACF Photo Gallery Field < 1.7.5 - Reflected Cross-Site Scripting
- CVE-2021-249102 PoCsTransposh WordPress Translation < 1.0.8 - Reflected Cross-Site Scripting
- CVE-2021-249111 PoCTransposh WordPress Translation < 1.0.8 - Stored Cross-Site Scripting
- CVE-2021-249121 PoCTransposh WordPress Translation < 1.0.8 - CSRF to Stored XSS
- CVE-2021-249131 PoCLogo Showcase with Slick Slider < 2.0.1 - Arbitrary Media Title/Description/Alt Text/URL Update via CSRF
- CVE-2021-249141 PoCTawk.to Live Chat < 0.6.0 - Subscriber+ Visitor Monitoring & Chat Removal
- CVE-2021-249153 PoCsContest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Email Address Disclosure
- CVE-2021-249162 PoCsQubely < 1.8.6 - Unauthenticated Arbitrary E-mail Sending
- CVE-2021-249176 PoCsWPS Hide Login < 1.9.1 - Protection Bypass with Referer-Header
- CVE-2021-249191 PoCWicked Folders < 2.18.10 - Subscriber+ SQL Injection
- CVE-2021-249201 PoCStatCounter < 2.0.7 - Admin+ Stored Cross-Site Scripting
- CVE-2021-249211 PoCAdvanced Database Cleaner < 3.0.4 - Reflected Cross-Site Scripting
- CVE-2021-249221 PoCPixel Cat Lite < 2.6.2 - CSRF to Stored Cross-Site Scripting
- CVE-2021-249231 PoCNewsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.25 - Reflected XSS
- CVE-2021-249241 PoCEmail Log < 2.4.8 - Reflected Cross-Site Scripting
- CVE-2021-249251 PoCModern Events Calendar Lite < 6.1.5 - Reflected Cross-Site Scripting
- CVE-2021-249263 PoCsDomain Check < 1.0.17 - Reflected Cross-Site Scripting
- CVE-2021-249271 PoCMy Calendar < 3.2.18 - Subscriber+ Reflected Cross-Site Scripting
- CVE-2021-249281 PoCRearrange Woocommerce Products < 3.0.8 - Subscriber+ SQL Injection
- CVE-2021-249301 PoCBookly < 20.3.1 - Staff Member Stored Cross-Site Scripting
- CVE-2021-249315 PoCsSecure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
- CVE-2021-249321 PoCAuto Featured Image < 3.9.3 - Reflected Cross-Site Scripting
- CVE-2021-249331 PoCDynamic Widgets <= 1.5.16 - Reflected Cross-Site Scripting
- CVE-2021-249342 PoCsVisual CSS Style Editor < 7.5.4 - Reflected Cross-Site Scripting
- CVE-2021-249351 PoCWP Google Fonts < 3.1.5 - Reflected Cross-Site Scripting
- CVE-2021-249361 PoCWP Extra File Types < 0.5.1 - CSRF to Stored Cross-Site Scripting
- CVE-2021-249371 PoCAsset CleanUp < 1.3.8.5 - Reflected Cross-Site Scripting
- CVE-2021-249381 PoCWooCommerce Currency Switcher < 1.3.7.1 - Reflected Cross-Site Scripting
- CVE-2021-249391 PoCLoginWP < 3.0.0.5 - Reflected Cross-Site Scripting
- CVE-2021-249402 PoCsPersian Woocommerce <= 5.8.0 - Reflected Cross-Site Scripting
- CVE-2021-249411 PoCIcegram < 2.0.5 - Reflected Cross-Site Scripting
- CVE-2021-249421 PoCMenu Item Visibility Control <= 0.5 - Admin+ Arbitrary PHP Code Execution
- CVE-2021-249432 PoCsRegistrations for the Events Calendar < 2.7.6 - Unauthenticated SQL Injection
- CVE-2021-249441 PoCCustom Dashboard & Login Page < 7.0 - Admin+ Stored Cross-Site Scripting
- CVE-2021-249451 PoCLike Button Rating < 2.6.38 - Unauthorised Vote Export to Email & IP Addresses Disclosure
- CVE-2021-249465 PoCsModern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection
- CVE-2021-249472 PoCsRVM - Responsive Vector Maps < 6.4.2 - Subscriber+ Arbitrary File Read
- CVE-2021-249481 PoCThe Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data Disclosure
- CVE-2021-249491 PoCThe Plus Addons for Elementor Pro < 5.0.7 - Unauthenticated SQL Injection
- CVE-2021-249501 PoCInsight Core <= 1.0 - Subscriber+ PHP Object Injection & Stored XSS
- CVE-2021-249511 PoCLearnPress < 4.1.4 - Admin+ SQL Injection
- CVE-2021-249521 PoCConversios.io < 4.6.2 - Subscriber+ SQL Injection
- CVE-2021-249531 PoCAdvanced iFrame < 2022 - Reflected Cross-Site Scripting
- CVE-2021-249541 PoCProfilePress < 3.2.3 - Reflected Cross-Site Scripting
- CVE-2021-249551 PoCProfilePress < 3.2.3 - Reflected Cross-Site Scripting
- CVE-2021-249562 PoCsBlog2Social < 6.8.7 - Reflected Cross-Site Scripting
- CVE-2021-249571 PoCAdvanced Page Visit Counter < 6.1.6 - Subscriber+ Blind SQL injection
- CVE-2021-249581 PoCMeks Easy Photo Feed Widget < 1.2.4 - Subscriber+ Settings Update to Stored XSS
- CVE-2021-249592 PoCsWP Email Users <= 1.7.6 - Subscriber+ SQL Injection
- CVE-2021-249601 PoCWordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Malicious SVG
- CVE-2021-249611 PoCWordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Shortcode
- CVE-2021-249621 PoCWordPress File Upload < 4.16.3 - Contributor+ Path Traversal to RCE
- CVE-2021-249631 PoCLiteSpeed Cache < 4.4.4 - Admin+ Reflected Cross-Site Scripting
- CVE-2021-249641 PoCLiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSS
- CVE-2021-249651 PoCFive Star Restaurant Reservations < 2.4.8 - Subscriber+ Stored Cross-Site Scripting
- CVE-2021-249662 PoCsError Log Viewer Plugin <= 1.1.1 - Admin+ Arbitrary File Clearing
- CVE-2021-249671 PoCContact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-249681 PoCUltimate FAQ < 2.1.2 - Subscriber+ Arbitrary FAQ Creation
- CVE-2021-249691 PoCDownload Manager < 3.2.22 - Subscriber+ Stored Cross-Site Scripting
- CVE-2021-249702 PoCsAll-In-One-Gallery < 2.5.0 - Admin+ Local File Inclusion
- CVE-2021-249711 PoCWP Responsive Menu < 3.1.7.1 - Subscriber+ Settings Update to Stored XSS
- CVE-2021-249721 PoCPixel Cat Lite < 2.6.3 - Admin+ Stored Cross-Site Scripting
- CVE-2021-249731 PoCSite Reviews < 5.17.3 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-249741 PoCProduct Feed PRO for WooCommerce < 11.0.7 - Subscriber+ Settings Update to Stored XSS
- CVE-2021-249751 PoCNextScripts: Social Networks Auto-Poster < 4.3.24 - Unauthenticated Stored XSS
- CVE-2021-249761 PoCSmart SEO Tool < 3.0.6 - Reflected Cross-Site Scripting
- CVE-2021-249771 PoCUse Any Font < 6.2.1 - Unauthenticated Arbitrary CSS Appending
- CVE-2021-249781 PoCOSMapper <= 2.1.5 - Unauthenticated Arbitrary Post Deletion
- CVE-2021-249792 PoCsPaid Memberships Pro < 2.6.6 - Reflected Cross-Site Scripting
- CVE-2021-249801 PoCGwolle Guestbook < 4.2.0 - Reflected Cross-Site Scripting
- CVE-2021-249811 PoCDirectorist – Business Directory Plugin < 7.0.6.2 - CSRF to Remote File Upload
- CVE-2021-249821 PoCChild Theme Generator <= 2.2.7 - Reflected Cross-Site Scripting
- CVE-2021-249831 PoCAsset CleanUp < 1.3.8.5 - Reflected Cross-Site Scripting via AJAX Action
- CVE-2021-249841 PoCWPFront User Role Editor < 3.2.1.11184 - Reflected Cross-Site Scripting
- CVE-2021-249851 PoCEasy Forms for Mailchimp < 6.8.6 - Reflected Cross-Site Scripting
- CVE-2021-249861 PoCPost Grid < 2.1.16 - Reflected Cross-Site Scripting via keyword
- CVE-2021-249872 PoCsSuper Socializer < 7.13.30 - Reflected Cross-Site Scripting
- CVE-2021-249881 PoCWP RSS Aggregator < 4.19.3 - Subscriber+ Stored Cross-Site Scripting
- CVE-2021-249891 PoCAccept Donations with PayPal < 1.3.4 - Arbitrary Post Deletion via CSRF
- CVE-2021-249912 PoCsWooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site Scripting
- CVE-2021-249921 PoCButtonizer - Smart Floating Action Button < 2.5.5 - Admin+ Stored Cross-Site Scripting
- CVE-2021-249931 PoCUltimate Product Catalog < 5.0.26 - Subscriber+ Arbitrary Product Creation & Settings Update
- CVE-2021-249941 PoCWPvivid Backup and Migration Plugin < 0.9.69 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-249951 PoCHTML5 Responsive FAQ <= 2.8.5 - Admin+ Stored Cross-Site Scripting
- CVE-2021-249961 PoCIDPay for Contact Form 7 <= 2.1.2 - Reflected Cross-Site Scripting
- CVE-2021-249973 PoCsWP Guppy < 1.3 - Sensitive Information Disclosure
- CVE-2021-249981 PoCSimple JWT Login < 3.3.0 - Insecure Password Creation
- CVE-2021-249991 PoCBooster for Woocommerce < 5.4.9 - Reflected Cross-Site Scripting in PDF Invoicing Module