Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2021-24179

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE.
Attacker Value
Unknown

CVE-2021-24250

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.
Attacker Value
Unknown

CVE-2021-24248

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE
Attacker Value
Unknown

CVE-2021-24249

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses etc
Attacker Value
Unknown

CVE-2021-24251

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)
Attacker Value
Unknown

CVE-2021-24178

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.
Attacker Value
Unknown

CVE-2019-15780

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
Attacker Value
Unknown

CVE-2014-10013

Disclosure Date: January 13, 2015 (last updated September 26, 2024)
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action.
0
Attacker Value
Unknown

CVE-2014-10012

Disclosure Date: January 13, 2015 (last updated September 26, 2024)
Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.
0