Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Button Generator – easily Button Builder | 2.3.3 ~ 2.3.3 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Button Generator before 2.3.3 within the wow-company admin menu page allows arbitrary file inclusion with PHP extensions (as well as with data:// or http:// protocols), thus leading to cross-site request forgery and remote code execution. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-25052.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-25054 | WPcalc <= 2.1 - Authenticated SQL Injection | |
| CVE-2021-25053 | WP Coder < 2.5.2 - RFI leading to RCE via CSRF | |
| CVE-2021-25051 | Modal Window < 5.2.2 - RFI leading to RCE via CSRF | |
| CVE-2021-25047 | 10Web Social Photo Feed < 1.4.29 - Reflected Cross-Site Scripting (XSS) | |
| CVE-2021-25043 | WOOCS < 1.3.7.3 - Reflected Cross-Site Scripting | |
| CVE-2021-24948 | The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data Disclosure | |
| CVE-2021-24949 | The Plus Addons for Elementor Pro < 5.0.7 - Unauthenticated SQL Injection | |
| CVE-2021-24862 | RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection | |
| CVE-2021-25032 | PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compr |
No comments yet