2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13315HIGH8.8The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2024-13852HIGH8.8The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin...
CVE-2024-13848MEDIUM4.8The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version...
CVE-2024-13725CRITICAL9.8The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc...
CVE-2024-13687MEDIUM4.3The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2024-13684HIGH8.1The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. Th...
CVE-2024-13677HIGH8.8The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege e...
CVE-2024-13622HIGH7.5The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2024-13609MEDIUM5.9The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive In...
CVE-2024-13595MEDIUM6.5The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode...
CVE-2024-13588MEDIUM5.4The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-13587MEDIUM5.4The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-13582MEDIUM5.4The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stor...
CVE-2024-13581MEDIUM5.4The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shor...
CVE-2024-13579MEDIUM5.4The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortc...
CVE-2024-13578MEDIUM5.4The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in...
CVE-2024-13577MEDIUM5.4The CATS Job Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catsone' short...
CVE-2024-13576MEDIUM5.4The Gumlet Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gumlet' shortcode i...
CVE-2024-13573MEDIUM5.4The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgf...
CVE-2024-13565MEDIUM5.4The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all...
CVE-2024-13555MEDIUM4.3The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site R...
CVE-2024-13540MEDIUM5.3The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path D...
CVE-2024-13538MEDIUM5.3The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all vers...
CVE-2024-13535MEDIUM5.3The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu...
CVE-2024-13522MEDIUM5.4The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now