2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1716MEDIUM4.3The Admin Bar Remover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-1688MEDIUM5.3The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ...
CVE-2024-1679MEDIUM5.4The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is ...
CVE-2024-1678MEDIUM5.3The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2024-1677HIGH8.8The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is ...
CVE-2024-1584MEDIUM5.3The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to...
CVE-2024-1572MEDIUM5.4The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_ulike' shortcode in ...
CVE-2024-1567CRITICAL9.8The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file ...
CVE-2024-1533MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-1416MEDIUM4.3The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access t...
CVE-2024-1415MEDIUM4.3The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Cross-Site Request Fo...
CVE-2024-1396MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-1386MEDIUM6.4The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-1348MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-1173HIGH7.2The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-0908MEDIUM5.3The Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page plugin for WordPress is vulnerable to unaut...
CVE-2024-0848MEDIUM6.1The AA Cash Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘invoice’ parameter ...
CVE-2024-0847MEDIUM4.3The 5280 Bootstrap Modal Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2024-0710MEDIUM5.3The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5....
CVE-2024-0629MEDIUM5.3The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data du...
CVE-2024-0615MEDIUM5.3The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin...
CVE-2024-0613MEDIUM6.1The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-4433MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple ...
CVE-2024-33530HIGH7.5In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the dis...
CVE-2024-32359MEDIUM6.9An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through design...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now