2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13473HIGH7.5The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship...
CVE-2024-13459MEDIUM5.4The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusedesk_newcase' short...
CVE-2024-13456MEDIUM5.4The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' sh...
CVE-2024-13437MEDIUM4.3The Book a Room plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2024-13435HIGH7.5The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up...
CVE-2024-13365CRITICAL9.8The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin ...
CVE-2024-12296HIGH8.8The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es...
CVE-2024-12213CRITICAL9.8The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is du...
CVE-2024-13814HIGH8.8The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode executio...
CVE-2024-12315HIGH7.5The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Expo...
CVE-2024-13821MEDIUM5.3The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in ...
CVE-2024-13794MEDIUM5.3The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all...
CVE-2024-13714HIGH8.8The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads...
CVE-2024-13601MEDIUM4.3The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecu...
CVE-2024-13600HIGH7.5The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensit...
CVE-2024-13374MEDIUM6.5The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thew...
CVE-2024-13800HIGH8.1The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of ser...
CVE-2024-13769MEDIUM5.4The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-13665MEDIUM5.4The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in...
CVE-2024-13658MEDIUM5.4The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_ne...
CVE-2024-13656HIGH8.1The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification ...
CVE-2024-13654HIGH8.1The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of dat...
CVE-2024-13653HIGH8.8The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of dat...
CVE-2024-13421CRITICAL9.8The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi...
CVE-2024-12164MEDIUM4.3The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now