Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) | 3.1.11 ~ 3.1.11 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The ProfilePress plugin for WordPress before 3.1.11 is vulnerable to unauthenticated reflected cross-site scripting (XSS) via the tabbed login/register widget due to improper escaping of user input. Attackers can inject arbitrary JavaScript via the tabbed-login-name parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24522.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24499 | Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution | |
| CVE-2021-24304 | Newsmag < 5.0 - Unauthenticated Reflected Cross-site Scripting (XSS) | |
| CVE-2021-24467 | Leaflet Map < 3.0.0 - Arbitrary Settings Update via CSRF Leading to Stored XSS | |
| CVE-2021-24495 | Marmoset Viewer < 1.9.3 - Reflected Cross Site Scripting | |
| CVE-2021-24500 | Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities | |
| CVE-2021-24501 | Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions | |
| CVE-2021-24502 | WP Google Map < 1.7.7 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24505 | Forms < 1.12.3 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24507 | Astra Pro Addon < 3.5.2 - Unauthenticated SQL Injection | |
| CVE-2021-24509 | Page View Counts < 2.4.9 - Contributor+ Stored XSS | |
| CVE-2021-24520 | Stock in & out <= 1.0.4 - Authenticated SQL Injection | |
| CVE-2021-24521 | Side Menu Lite < 2.2.1 - Authenticated SQL Injection |
No comments yet