2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3047HIGH7.2The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in ve...
CVE-2024-3045MEDIUM6.1The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s...
CVE-2024-3023MEDIUM4.4The AnnounceKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2024-3021MEDIUM4.4The Mhr Post Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Header Title value in all ...
CVE-2024-33949MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vark Min and Max P...
CVE-2024-33948MEDIUM5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixel Industry Twe...
CVE-2024-2967MEDIUM4.4The Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor plugin for WordPress is vuln...
CVE-2024-2960MEDIUM4.3The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-2959MEDIUM4.3The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-2958MEDIUM4.8The SVS Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via pricing table settings in a...
CVE-2024-2876CRITICAL9.8The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-2867MEDIUM5.4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2024-2840MEDIUM5.4The Enhanced Media Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload functional...
CVE-2024-2831HIGH8.8The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and ...
CVE-2024-2797MEDIUM5.3The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due t...
CVE-2024-2790MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accord...
CVE-2024-2765MEDIUM5.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-2752MEDIUM5.5The Where Did You Hear About Us Checkout Field for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-2751MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infob...
CVE-2024-2750MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribu...
CVE-2024-2667CRITICAL9.8The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to...
CVE-2024-2661HIGH8.8The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plug...
CVE-2024-2542MEDIUM6.4The Jotform Online Forms – Drag & Drop Form Builder, Securely Embed Contact Forms plugin for WordPress is vulnerable to ...
CVE-2024-2503MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid W...
CVE-2024-2417HIGH8.8The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now