Vulnerabilities with Nuclei Scanner Templates
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
4,077 results
Clear all
CVE-2021-24940
6.1
MEDIUM
NUCLEI
EPSS 0.02
Persian Woocommerce <5.8.0 - XSS
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue
CWE-79
Mar 14, 2022
CVE-2021-25118
5.3
MEDIUM
NUCLEI
EPSS 0.35
Yoast SEO <17.2 - Info Disclosure
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.
CWE-200
Feb 28, 2022
CVE-2021-25112
6.1
MEDIUM
NUCLEI
EPSS 0.05
WHMCS Bridge <6.4b - XSS
The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting
CWE-79
Feb 28, 2022
CVE-2021-25099
6.1
MEDIUM
NUCLEI
EPSS 0.02
GiveWP <2.17.3 - XSS
The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting
CWE-79
Feb 21, 2022
CVE-2021-25082
8.8
HIGH
EXPLOITED
NUCLEI
EPSS 0.20
Popup Builder WordPress <4.0.7 - Code Injection
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR
CWE-22
Feb 21, 2022
CVE-2021-25075
3.5
LOW
NUCLEI
EPSS 0.12
WordPress Duplicate Page/Post <1.5.1 - CSRF
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues
CWE-862
Feb 21, 2022
CVE-2021-25055
6.1
MEDIUM
NUCLEI
EPSS 0.02
FeedWordPress <2022.0123 - XSS
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
CWE-79
Feb 21, 2022
CVE-2021-25033
6.1
MEDIUM
NUCLEI
EPSS 0.01
WordPress Newsletter Plugin <1.6.5 - Open Redirect
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue
CWE-601
Feb 14, 2022
CVE-2021-25114
9.8
CRITICAL
EXPLOITED
NUCLEI
EPSS 0.79
Paid Memberships Pro <2.6.7 - SQL Injection
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection
CWE-89
Feb 07, 2022
CVE-2021-24947
6.5
MEDIUM
NUCLEI
EPSS 0.10
RVM WordPress <6.4.2 - Info Disclosure
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server
CWE-434
Feb 07, 2022
CVE-2021-24878
6.1
MEDIUM
EXPLOITED
NUCLEI
EPSS 0.00
SupportCandy WP <2.2.7 - XSS
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue
CWE-79
Feb 07, 2022
CVE-2021-25085
6.1
MEDIUM
NUCLEI
EPSS 0.03
WOOF <1.2.6.3 - XSS
The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting
CWE-79
Feb 01, 2022
CVE-2021-25063
6.1
MEDIUM
NUCLEI
EPSS 0.01
Skins for Contact Form 7 <2.5.1 - XSS
The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
CWE-79
Feb 01, 2022
CVE-2021-24934
6.1
MEDIUM
NUCLEI
EPSS 0.04
Visual CSS Style Editor <7.5.4 - XSS
The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
CWE-79
Feb 01, 2022
CVE-2021-24926
6.1
MEDIUM
1 PoC
Analysis
NUCLEI
EPSS 0.08
Domain Check WP <1.0.17 - XSS
The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue
CWE-79
Feb 01, 2022
CVE-2021-24762
9.8
CRITICAL
EXPLOITED
4 PoCs
Analysis
NUCLEI
EPSS 0.86
The Perfect Survey WP <1.5.2 - SQL Injection
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.
CWE-89
Feb 01, 2022
CVE-2021-25079
6.1
MEDIUM
NUCLEI
EPSS 0.01
Contact Form Entries <1.2.4 - Info Disclosure
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page
CWE-79
Jan 24, 2022
CVE-2021-25078
6.1
MEDIUM
NUCLEI
EPSS 0.06
WordPress Affiliates Manager <2.9.0 - XSS
The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.
CWE-79
Jan 24, 2022
CVE-2021-25074
6.1
MEDIUM
NUCLEI
EPSS 0.01
WebP Converter for Media <4.0.3 - Open Redirect
The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue
CWE-601
Jan 24, 2022
CVE-2021-25028
6.1
MEDIUM
NUCLEI
EPSS 0.04
Event Tickets WP <5.2.2 - CSRF
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue
CWE-601
Jan 24, 2022