2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3520MEDIUM4.3The Country State City Dropdown CF7 plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-3517MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-3500HIGH8.8The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6...
CVE-2024-3499HIGH8.8The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i...
CVE-2024-3489MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdow...
CVE-2024-3473MEDIUM6.1The Header Footer Code Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message ...
CVE-2024-3341MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-3340MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri-gal...
CVE-2024-3338MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt data parameter ...
CVE-2024-3337MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_bre...
CVE-2024-3312MEDIUM5.3The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...
CVE-2024-3308MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Im...
CVE-2024-3307MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Co...
CVE-2024-3295MEDIUM6.5The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ...
CVE-2024-3287MEDIUM5.3The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to unauthorized ld+...
CVE-2024-3275MEDIUM4.3The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all version...
CVE-2024-3233MEDIUM4.3The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2024-3215MEDIUM4.3The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2024-3206MEDIUM4.3The Different Menu in Different Pages – Control Menu Visibility (All in One) plugin for WordPress is vulnerable to unaut...
CVE-2024-3199MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown wi...
CVE-2024-3197MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attribute...
CVE-2024-3161MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's attri...
CVE-2024-3107MEDIUM4.3The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and inc...
CVE-2024-3074MEDIUM6.4The Elementor ImageBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image box widget in all...
CVE-2024-3071MEDIUM4.3The ACF On-The-Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now