2023 CVE Vulnerabilities
31,411 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-2402 | MEDIUM | 6.1 | 0.4% | Jun 9, 2023 | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting... |
| CVE-2023-2305 | MEDIUM | 5.4 | 0.6% | Jun 9, 2023 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_log... |
| CVE-2023-2289 | MEDIUM | 6.1 | 0.4% | Jun 9, 2023 | The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search... |
| CVE-2023-2280 | MEDIUM | 5.3 | 0.6% | Jun 9, 2023 | The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a m... |
| CVE-2023-2275 | MEDIUM | 5.4 | 0.5% | Jun 9, 2023 | The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and... |
| CVE-2023-2249 | HIGH | 8.8 | 60.8% | Jun 9, 2023 | The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deseria... |
| CVE-2023-2237 | HIGH | 8.8 | 0.8% | Jun 9, 2023 | The WP Replicate Post plugin for WordPress is vulnerable to SQL Injection via the post_id parameter in versions up to, a... |
| CVE-2023-2189 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2023-2184 | MEDIUM | 6.1 | 0.4% | Jun 9, 2023 | The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site... |
| CVE-2023-2159 | MEDIUM | 5.3 | 0.8% | Jun 9, 2023 | The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and... |
| CVE-2023-2087 | MEDIUM | 4.3 | 0.3% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2023-2086 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability... |
| CVE-2023-2085 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability... |
| CVE-2023-2084 | MEDIUM | 4.3 | 0.5% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability... |
| CVE-2023-2083 | MEDIUM | 4.3 | 0.6% | Jun 9, 2023 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability... |
| CVE-2023-2067 | MEDIUM | 5.4 | 0.3% | Jun 9, 2023 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due t... |
| CVE-2023-2066 | MEDIUM | 4.3 | 0.5% | Jun 9, 2023 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modifica... |
| CVE-2023-2031 | MEDIUM | 5.4 | 0.5% | Jun 9, 2023 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod... |
| CVE-2023-1978 | MEDIUM | 6.1 | 0.4% | Jun 9, 2023 | The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t... |
| CVE-2023-1917 | MEDIUM | 5.4 | 0.5% | Jun 9, 2023 | The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio... |
| CVE-2023-1910 | MEDIUM | 4.3 | 0.5% | Jun 9, 2023 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insuffic... |
| CVE-2023-1895 | CRITICAL | 9.6 | 0.6% | Jun 9, 2023 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_conte... |
| CVE-2023-1889 | MEDIUM | 6.5 | 0.6% | Jun 9, 2023 | The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and includi... |
| CVE-2023-1888 | HIGH | 8.8 | 1.0% | Jun 9, 2023 | The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including,... |
| CVE-2023-1843 | MEDIUM | 5.3 | 0.6% | Jun 9, 2023 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now