2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13336MEDIUM4.3The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-13231MEDIUM5.3The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2024-13854MEDIUM4.3The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions...
CVE-2024-13736MEDIUM6.1The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWid...
CVE-2024-13719MEDIUM5.3The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ...
CVE-2024-13712MEDIUM4.9The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and i...
CVE-2024-13711MEDIUM6.1The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all vers...
CVE-2024-13679MEDIUM5.4The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' sh...
CVE-2024-13676MEDIUM6.5The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'ima...
CVE-2024-13674MEDIUM6.4The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-13663MEDIUM6.4The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' s...
CVE-2024-13660MEDIUM6.4The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fsho...
CVE-2024-13657MEDIUM6.4The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocato...
CVE-2024-13592HIGH8.8The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File In...
CVE-2024-13591MEDIUM5.4The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-...
CVE-2024-13589MEDIUM6.4The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt...
CVE-2024-13468HIGH7.5The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing ca...
CVE-2024-13462MEDIUM6.4The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode ...
CVE-2024-13405MEDIUM4.3The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-13390MEDIUM6.4The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-12522MEDIUM6.4The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-12339MEDIUM6.1The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' paramet...
CVE-2024-12069MEDIUM6.1The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou...
CVE-2024-11778MEDIUM6.4The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2024-11753MEDIUM6.4The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_butt...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now