2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6855 | MEDIUM | 5.3 | 0.5% | Jan 11, 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab... |
| CVE-2023-6828 | MEDIUM | 6.1 | 0.4% | Jan 11, 2024 | The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to... |
| CVE-2023-6782 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2023-6781 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fie... |
| CVE-2023-6776 | MEDIUM | 5.4 | 0.3% | Jan 11, 2024 | The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all ... |
| CVE-2023-6751 | MEDIUM | 6.5 | 0.4% | Jan 11, 2024 | The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability chec... |
| CVE-2023-6742 | MEDIUM | 4.3 | 0.4% | Jan 11, 2024 | The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2023-6737 | MEDIUM | 6.1 | 0.5% | Jan 11, 2024 | The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG p... |
| CVE-2023-6684 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' s... |
| CVE-2023-6645 | MEDIUM | 5.4 | 0.3% | Jan 11, 2024 | The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cus... |
| CVE-2023-6638 | MEDIUM | 5.3 | 0.5% | Jan 11, 2024 | The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2023-6637 | MEDIUM | 5.3 | 0.5% | Jan 11, 2024 | The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2023-6636 | HIGH | 7.2 | 1.3% | Jan 11, 2024 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to m... |
| CVE-2023-6634 | CRITICAL | 9.8 | 8.5% | Jan 11, 2024 | The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via... |
| CVE-2023-6632 | MEDIUM | 6.1 | 0.5% | Jan 11, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versi... |
| CVE-2023-6624 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2023-6598 | MEDIUM | 4.3 | 0.4% | Jan 11, 2024 | The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2023-6583 | HIGH | 7.2 | 0.8% | Jan 11, 2024 | The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up t... |
| CVE-2023-6582 | MEDIUM | 5.3 | 0.5% | Jan 11, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2023-6567 | HIGH | 7.5 | 51.4% | Jan 11, 2024 | The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versio... |
| CVE-2023-6561 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the featured im... |
| CVE-2023-6558 | HIGH | 7.2 | 1.4% | Jan 11, 2024 | The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficie... |
| CVE-2023-6556 | MEDIUM | 5.4 | 0.4% | Jan 11, 2024 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2023-6504 | MEDIUM | 4.3 | 0.3% | Jan 11, 2024 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2023-6496 | MEDIUM | 5.3 | 0.5% | Jan 11, 2024 | The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now