2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2414 | MEDIUM | 4.3 | 0.5% | Jun 9, 2023 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2023-2402 | MEDIUM | 6.1 | 0.4% | Jun 9, 2023 | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting... |
| CVE-2023-2305 | MEDIUM | 5.4 | 0.6% | Jun 9, 2023 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_log... |
| CVE-2023-2289 | MEDIUM | 6.1 | 0.4% | Jun 9, 2023 | The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search... |
| CVE-2023-2280 | MEDIUM | 5.3 | 0.6% | Jun 9, 2023 | The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a m... |
| CVE-2023-2275 | MEDIUM | 5.4 | 0.5% | Jun 9, 2023 | The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and... |
| CVE-2023-2189 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2023-2184 | MEDIUM | 6.1 | 0.4% | Jun 9, 2023 | The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site... |
| CVE-2023-2159 | MEDIUM | 5.3 | 0.8% | Jun 9, 2023 | The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and... |
| CVE-2023-2087 | MEDIUM | 4.3 | 0.3% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2023-2086 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability... |
| CVE-2023-2085 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability... |
| CVE-2023-2084 | MEDIUM | 4.3 | 0.5% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability... |
| CVE-2023-2083 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability... |
| CVE-2023-2067 | MEDIUM | 5.4 | 0.3% | Jun 9, 2023 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due t... |
| CVE-2023-2066 | MEDIUM | 4.3 | 0.5% | Jun 9, 2023 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modifica... |
| CVE-2023-2031 | MEDIUM | 5.4 | 0.5% | Jun 9, 2023 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod... |
| CVE-2023-1978 | MEDIUM | 6.1 | 0.4% | Jun 9, 2023 | The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t... |
| CVE-2023-1917 | MEDIUM | 5.4 | 0.5% | Jun 9, 2023 | The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio... |
| CVE-2023-1910 | MEDIUM | 4.3 | 0.5% | Jun 9, 2023 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insuffic... |
| CVE-2023-1889 | MEDIUM | 6.5 | 0.6% | Jun 9, 2023 | The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and includi... |
| CVE-2023-1843 | MEDIUM | 5.3 | 0.6% | Jun 9, 2023 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update... |
| CVE-2023-1807 | MEDIUM | 4.3 | 0.3% | Jun 9, 2023 | The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2023-1615 | MEDIUM | 6.5 | 0.8% | Jun 9, 2023 | The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in ver... |
| CVE-2023-1430 | MEDIUM | 6.5 | 0.8% | Jun 9, 2023 | The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of d... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now