2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-6924MEDIUM4.8The Photo Gallery by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in versions up ...
CVE-2023-6882MEDIUM6.1The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ pa...
CVE-2023-6878MEDIUM6.5The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2023-6855MEDIUM5.3The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2023-6828MEDIUM6.1The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to...
CVE-2023-6782MEDIUM5.4The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2023-6781MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fie...
CVE-2023-6776MEDIUM5.4The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all ...
CVE-2023-6751MEDIUM6.5The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability chec...
CVE-2023-6742MEDIUM4.3The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2023-6737MEDIUM6.1The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG p...
CVE-2023-6684MEDIUM5.4The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' s...
CVE-2023-6645MEDIUM5.4The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cus...
CVE-2023-6638MEDIUM5.3The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2023-6637MEDIUM5.3The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2023-6632MEDIUM6.1The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versi...
CVE-2023-6624MEDIUM5.4The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2023-6598MEDIUM4.3The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2023-6582MEDIUM5.3The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2023-6561MEDIUM5.4The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured im...
CVE-2023-6556MEDIUM5.4The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2023-6504MEDIUM4.3The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2023-6496MEDIUM5.3The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i...
CVE-2023-6369MEDIUM5.4The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to unauthorized access of data and modification...
CVE-2023-5691MEDIUM4.8The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now