2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1133MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restri...
CVE-2024-1130MEDIUM4.3The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized a...
CVE-2024-1129MEDIUM4.3The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized a...
CVE-2024-1128LOW3.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all version...
CVE-2024-1091MEDIUM4.3The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2024-1090MEDIUM4.3The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2024-1089MEDIUM4.3The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2024-1070MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the features attribu...
CVE-2024-1058MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the onclick paramete...
CVE-2024-1054MEDIUM5.4The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wcj_pr...
CVE-2024-1044MEDIUM5.3The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi...
CVE-2024-1043MEDIUM6.5The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missi...
CVE-2024-0984MEDIUM4.3The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2024-0983MEDIUM4.3The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2024-0978MEDIUM5.3The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl...
CVE-2024-0907MEDIUM4.3The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized a...
CVE-2024-0838MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL ...
CVE-2024-0821MEDIUM6.1The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected ...
CVE-2024-0792MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-0702HIGH7.3The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to miss...
CVE-2024-0658MEDIUM4.8The Insert PHP Code Snippet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's name when a...
CVE-2024-0656MEDIUM4.8The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vu...
CVE-2024-0621MEDIUM4.8The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a...
CVE-2024-0620MEDIUM5.3The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u...
CVE-2024-0616MEDIUM5.3The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now