2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6855MEDIUM5.3The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2023-6828MEDIUM6.1The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to...
CVE-2023-6782MEDIUM5.4The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2023-6781MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fie...
CVE-2023-6776MEDIUM5.4The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all ...
CVE-2023-6751MEDIUM6.5The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability chec...
CVE-2023-6742MEDIUM4.3The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2023-6737MEDIUM6.1The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG p...
CVE-2023-6684MEDIUM5.4The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' s...
CVE-2023-6645MEDIUM5.4The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cus...
CVE-2023-6638MEDIUM5.3The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2023-6637MEDIUM5.3The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2023-6636HIGH7.2The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to m...
CVE-2023-6634CRITICAL9.8The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via...
CVE-2023-6632MEDIUM6.1The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versi...
CVE-2023-6624MEDIUM5.4The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2023-6598MEDIUM4.3The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2023-6583HIGH7.2The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up t...
CVE-2023-6582MEDIUM5.3The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2023-6567HIGH7.5The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versio...
CVE-2023-6561MEDIUM5.4The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured im...
CVE-2023-6558HIGH7.2The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficie...
CVE-2023-6556MEDIUM5.4The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2023-6504MEDIUM4.3The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2023-6496MEDIUM5.3The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now