Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Secure Copy Content Protection and Content Locking | 2.8.2 ~ 2.8.2 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Secure Copy Content Protection and Content Locking plugin before 2.8.2 contains a SQL injection vulnerability. The plugin does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action, available to both unauthenticated and authenticated users, before using it in a SQL statement. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24931.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24714 | WP All Import < 3.6.3 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24718 | ARForms Form Builder < 1.5 - Admin+ Stored Cross Site Scripting | |
| CVE-2021-24759 | PDF.js Viewer < 2.0.2 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24866 | WP Data Access < 5.0.0 - Admin+ SQL Injection | |
| CVE-2021-24914 | Tawk.to Live Chat < 0.6.0 - Subscriber+ Visitor Monitoring & Chat Removal | |
| CVE-2021-24917 | WPS Hide Login < 1.9.1 - Protection Bypass with Referer-Header | |
| CVE-2021-24924 | Email Log < 2.4.8 - Reflected Cross-Site Scripting | |
| CVE-2021-24930 | Bookly < 20.3.1 - Staff Member Stored Cross-Site Scripting | |
| CVE-2021-24935 | WP Google Fonts < 3.1.5 - Reflected Cross-Site Scripting | |
| CVE-2021-24938 | WooCommerce Currency Switcher < 1.3.7.1 - Reflected Cross-Site Scripting | |
| CVE-2021-24939 | LoginWP < 3.0.0.5 - Reflected Cross-Site Scripting | |
| CVE-2021-24943 | Registrations for the Events Calendar < 2.7.6 - Unauthenticated SQL Injection | |
| CVE-2021-25041 | Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS) |
No comments yet