Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | eCommerce Product Catalog Plugin for WordPress | 3.0.39 ~ 3.0.39 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress eCommerce Product Catalog plugin before 3.0.39 contains a cross-site scripting vulnerability. The plugin does not escape the ic-settings-search parameter before outputting it back in the page in an attribute. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24875.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24641 | Images to WebP < 1.9 - Multiple Cross Site Request Forgery (CSRF) | |
| CVE-2021-24644 | Images to WebP < 1.9 - Authenticated Local File Inclusion | |
| CVE-2021-24668 | MAZ Loader < 1.4.1 - Arbitrary Loader Deletion via CSRF | |
| CVE-2021-24700 | Forminator < 1.15.4 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24703 | Download Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin Activation | |
| CVE-2021-24729 | Logo Showcase with Slick Slider < 1.2.4 - Author+ Stored Cross Site Scripting | |
| CVE-2021-24812 | BetterLinks < 1.2.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24830 | Advanced Access Manager < 6.8.0 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24873 | Tutor LMS < 1.9.11 - Reflected Cross-Site Scripting | |
| CVE-2021-24877 | MainWP Child < 4.1.8 - Admin+ SQL Injection | |
| CVE-2021-24882 | Slideshow Gallery < 1.7.4 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24888 | ImageBoss < 3.0.6 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24891 | Elementor < 3.4.8 - DOM Cross-Site-Scripting | |
| CVE-2021-24894 | Reviews Plus < 1.2.14 - Subscriber+ Reviews DoS |
No comments yet