2023 CVE Vulnerabilities

31,397 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-6164MEDIUM4.8The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS In...
CVE-2023-6160MEDIUM6.7The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions...
CVE-2023-6009HIGH8.8The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to in...
CVE-2023-6008MEDIUM4.3The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. Th...
CVE-2023-6007MEDIUM6.5The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to...
CVE-2023-5822CRITICAL9.8The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due...
CVE-2023-5815CRITICAL9.8The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post...
CVE-2023-5742MEDIUM5.4The EasyRotator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyro...
CVE-2023-5715MEDIUM4.8The Website Optimization – Plerdy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tra...
CVE-2023-5708MEDIUM5.4The WP Post Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'column' shortcod...
CVE-2023-5706MEDIUM5.4The VK Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vk-blocks/ancestor-pag...
CVE-2023-5704MEDIUM5.4The CPO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all ...
CVE-2023-5667MEDIUM5.4The Tab Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all ve...
CVE-2023-5664MEDIUM5.4The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ggpkg' shor...
CVE-2023-5662MEDIUM5.4The Sponsors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sponsors' shortcode in ...
CVE-2023-5537MEDIUM4.3The Delete Usermeta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2023-5469MEDIUM5.4The Drop Shadow Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dropshadowbox' shortcode in...
CVE-2023-5466HIGH8.8The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,...
CVE-2023-5465HIGH8.8The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to...
CVE-2023-5419MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2023-5417MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2023-5416MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2023-5415MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2023-5411MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2023-5387MEDIUM4.3The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now