2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24925MEDIUM6.1The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider par...
CVE-2021-24922CRITICAL9The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as w...
CVE-2021-24896MEDIUM4.8The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attri...
CVE-2021-24872MEDIUM6.5The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other p...
CVE-2021-24871MEDIUM5.4The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the pa...
CVE-2021-24863CRITICAL9.8The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before ...
CVE-2021-24861HIGH7.2The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using i...
CVE-2021-24859MEDIUM4.3The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as c...
CVE-2021-24857CRITICAL9.8The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which ...
CVE-2021-24855MEDIUM5.4The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their conte...
CVE-2021-24848HIGH8.8The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authentic...
CVE-2021-24845MEDIUM6.5The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status ...
CVE-2021-24836MEDIUM4.3The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when upda...
CVE-2021-24819MEDIUM4.3The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users...
CVE-2021-24818MEDIUM4.3The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make ...
CVE-2021-24817MEDIUM5.4The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, ...
CVE-2021-24795MEDIUM6.5The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleti...
CVE-2021-24792MEDIUM6.1The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a templat...
CVE-2021-24790MEDIUM4.3The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks...
CVE-2021-24784MEDIUM6.5The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could al...
CVE-2021-24782MEDIUM4.8The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could...
CVE-2021-24780MEDIUM4.3The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could ...
CVE-2021-24771MEDIUM4.8The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields whe...
CVE-2021-24756MEDIUM6.1The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from lo...
CVE-2021-24747HIGH7.2The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now