Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2021-24829

Disclosure Date: November 08, 2021 (last updated November 28, 2024)
The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue
Attacker Value
Unknown

CVE-2021-24188

Disclosure Date: May 14, 2021 (last updated November 28, 2024)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
Attacker Value
Unknown

CVE-2021-24194

Disclosure Date: May 14, 2021 (last updated November 28, 2024)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
Attacker Value
Unknown

CVE-2021-24195

Disclosure Date: May 14, 2021 (last updated November 28, 2024)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
Attacker Value
Unknown

CVE-2021-24193

Disclosure Date: May 14, 2021 (last updated November 28, 2024)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
Attacker Value
Unknown

CVE-2021-24190

Disclosure Date: May 14, 2021 (last updated November 28, 2024)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
Attacker Value
Unknown

CVE-2021-24189

Disclosure Date: May 14, 2021 (last updated November 28, 2024)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
Attacker Value
Unknown

CVE-2019-15831

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
0
Attacker Value
Unknown

CVE-2019-15832

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
0