Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown
CVE-2021-24847
Disclosure Date: November 17, 2021 (last updated November 08, 2023)
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed
0
Attacker Value
Unknown
CVE-2021-24327
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads
0
Attacker Value
Unknown
CVE-2021-24325
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.
0
Attacker Value
Unknown
CVE-2021-24282
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a form, and more.
0
Attacker Value
Unknown
CVE-2021-24280
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.
0
Attacker Value
Unknown
CVE-2021-24281
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.
0
Attacker Value
Unknown
CVE-2021-24278
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.
0
Attacker Value
Unknown
CVE-2021-24279
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.
0
Attacker Value
Unknown
CVE-2021-24187
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.
0
Attacker Value
Unknown
CVE-2011-5329
Disclosure Date: August 28, 2019 (last updated November 27, 2024)
The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562.
0