2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-2402MEDIUM6.1The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
CVE-2023-2305MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_log...
CVE-2023-2289MEDIUM6.1The wordpress vertical image slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search...
CVE-2023-2280MEDIUM5.3The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a m...
CVE-2023-2275MEDIUM5.4The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and...
CVE-2023-2249HIGH8.8The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deseria...
CVE-2023-2237HIGH8.8The WP Replicate Post plugin for WordPress is vulnerable to SQL Injection via the post_id parameter in versions up to, a...
CVE-2023-2189MEDIUM4.3The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2023-2184MEDIUM6.1The WP Responsive Tabs horizontal vertical and accordion Tabs plugin for WordPress is vulnerable to Reflected Cross-Site...
CVE-2023-2159MEDIUM5.3The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and...
CVE-2023-2087MEDIUM4.3The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2023-2086MEDIUM4.3The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability...
CVE-2023-2085MEDIUM4.3The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability...
CVE-2023-2084MEDIUM4.3The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability...
CVE-2023-2083MEDIUM4.3The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability...
CVE-2023-2067MEDIUM5.4The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due t...
CVE-2023-2066MEDIUM4.3The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to unauthorized access and modifica...
CVE-2023-2031MEDIUM5.4The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcod...
CVE-2023-1978MEDIUM6.1The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t...
CVE-2023-1917MEDIUM5.4The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versio...
CVE-2023-1910MEDIUM4.3The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insuffic...
CVE-2023-1895CRITICAL9.6The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_conte...
CVE-2023-1889MEDIUM6.5The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and includi...
CVE-2023-1888HIGH8.8The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including,...
CVE-2023-1843MEDIUM5.3The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now