
CVE-2021-25102 – All In One WP Security < 4.4.11 - Authenticated Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-25102
11 Apr 2022 — The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the risk El plugin All In One WP Security & Firewall d... • https://wpscan.com/vulnerability/9b8a00a6-622b-4309-bbbf-fe2c7fc9f8b6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24694 – Simple Download Monitor < 3.9.11 - Contributor+ Stored Cross-Site Scripting via Shortcodes
https://notcve.org/view.php?id=CVE-2021-24694
21 Dec 2021 — The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode. El plugin Simple Download Monitor de WordPress versiones anteriores a 3.9.11, podía permitir a usuarios con un rol tan bajo como el de Contribuyente llevar a cabo un ataque de tipo Cross-Site Scripting Almacenado por medio... • https://wpscan.com/vulnerability/9d0d8f8c-f8fb-457f-b557-255a052ccc32 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24696 – Simple Download Monitor < 3.9.9 - Multiple CSRF
https://notcve.org/view.php?id=CVE-2021-24696
21 Dec 2021 — The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads El plugin Simple Download Monitor de WordPress versiones anteriores a 3.9.9, no aplica las comprobaciones de nonce, lo que podría permitir a atacantes llevar a cabo ataques de tipo CSRF para 1) hace... • https://wpscan.com/vulnerability/e94772af-39ac-4743-a556-52351ebda9fe • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2021-24693 – Simple Download Monitor < 3.9.5 - Contributor+ Stored Cross-Site Scripting via File Thumbnail
https://notcve.org/view.php?id=CVE-2021-24693
05 Oct 2021 — The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review state, contributor could make JavaScript code execute in a context of a reviewer such as admin and make them create a rogue admin account, or install a malicious plugin El plugin Simple Download ... • https://wpscan.com/vulnerability/4bb559b7-8dde-4c90-a9a6-d8dcfbea53a7 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24695 – Simple Download Monitor < 3.9.6 - Unauthenticated Log Access
https://notcve.org/view.php?id=CVE-2021-24695
05 Oct 2021 — The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames El plugin Simple Download Monitor de WordPress versiones anteriores a 3.9.6, guarda los registros en una ubicación predecible y no presenta ninguna autenticación o autorización para evitar que los usuarios no autenticados ... • https://wpscan.com/vulnerability/d7bdaf2b-cdd9-4aee-b1bb-01728160ff25 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-425: Direct Request ('Forced Browsing') •

CVE-2021-24697 – Simple Download Monitor < 3.9.5 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24697
05 Oct 2021 — The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues El plugin Simple Download Monitor de WordPress versiones anteriores a 3.9.5, no escapa de los parámetros 1) sdm_active_tab GET y 2) sdm_stats_start_date/sdm_stats_end_date POST antes de devolverlos en atributos, conllevando a problemas de tipo Cro... • https://wpscan.com/vulnerability/ef9ae513-6c29-45c2-b5ae-4a06a217c499 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24698 – Simple Download Monitor < 3.9.6 - Arbitrary Thumbnails Removal
https://notcve.org/view.php?id=CVE-2021-24698
05 Oct 2021 — The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download. El plugin Simple Download Monitor de WordPress versiones anteriores a 3.9.6, permite a usuarios con un rol tan bajo como el de Contribuyente eliminar las miniaturas de las descargas de las que no son propietarios, incluso si normalmente no pueden editar la descarga • https://wpscan.com/vulnerability/1fda1356-77d8-4e77-9ee6-8f9ceeb3d380 • CWE-284: Improper Access Control •

CVE-2021-24799 – Far Future Expiry Header < 1.5 - Plugin's Settings Update via CSRF
https://notcve.org/view.php?id=CVE-2021-24799
04 Oct 2021 — The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. El plugin Far Future Expiry Header de WordPress versiones anteriores a 1.5 no presenta una comprobación de tipo CSRF cuando guarda sus ajustes, lo que podría permitir a atacantes hacer que un administrador conectado los cambie por medio de un ataque de tipo CSRF • https://wpscan.com/vulnerability/6010ce4e-3e46-4cc1-96d8-560b30b605ed • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2021-24734 – Compact WP Audio Player < 1.9.7 - Contributor+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24734
15 Sep 2021 — The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. El plugin Compact WP Audio Player de WordPress versiones anteriores a 1.9.7, no escapa a algunos de sus atributos de shortcodes, que podría permitir a usuarios con un rol tan bajo como el de Contribuyente llevar a cabo ataques de tipo Cross-Site Scripting Almacenado • https://wpscan.com/vulnerability/fb007191-b008-4d19-b896-55fbee2a3cf7 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24735 – Compact WP Audio Player < 1.9.7 - Setting Change via CSRF
https://notcve.org/view.php?id=CVE-2021-24735
15 Sep 2021 — The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack. El plugin Compact WP Audio Player de WordPress versiones anteriores a 1.9.7, no implementa comprobaciones de nonce, que podría permitir a atacantes hacer que un administrador conectado cambie el ajuste "Disable Simultaneous Play" por medio de un ataque de tipo CSRF • https://wpscan.com/vulnerability/dcbcf6e7-e5b3-498b-9f5e-7896d309441f • CWE-352: Cross-Site Request Forgery (CSRF) •