2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10583 | MEDIUM | 5.4 | 0.3% | Dec 12, 2024 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress... |
| CVE-2024-9881 | MEDIUM | 4.8 | 0.4% | Dec 12, 2024 | The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-9641 | MEDIUM | 4.8 | 0.4% | Dec 12, 2024 | The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which cou... |
| CVE-2024-9428 | MEDIUM | 4.8 | 0.3% | Dec 12, 2024 | The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2024-12265 | MEDIUM | 5.3 | 0.4% | Dec 12, 2024 | The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due ... |
| CVE-2024-12263 | MEDIUM | 4.3 | 0.3% | Dec 12, 2024 | The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-12255 | MEDIUM | 5.3 | 0.5% | Dec 12, 2024 | The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versio... |
| CVE-2024-12072 | MEDIUM | 6.1 | 0.3% | Dec 12, 2024 | The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due ... |
| CVE-2024-12059 | MEDIUM | 4.3 | 0.3% | Dec 12, 2024 | The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers... |
| CVE-2024-12018 | MEDIUM | 4.3 | 0.4% | Dec 12, 2024 | The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorizatio... |
| CVE-2024-11882 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The FAQ And Answers – Create Frequently Asked Questions Area on WP Sites plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-11871 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'patreon'... |
| CVE-2024-11785 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The Integrate Firebase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'firebase_show... |
| CVE-2024-11781 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2024-11766 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more plugin for WordPress is vuln... |
| CVE-2024-11765 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more plugin for Wor... |
| CVE-2024-11757 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The WP GeoNames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-geonames' shortco... |
| CVE-2024-11359 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Library Bookshelves plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-11052 | MEDIUM | 6.1 | 0.3% | Dec 12, 2024 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-10637 | MEDIUM | 5.4 | 0.3% | Dec 12, 2024 | The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its bloc... |
| CVE-2024-10568 | MEDIUM | 4.7 | 0.4% | Dec 12, 2024 | The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-10518 | MEDIUM | 4.8 | 0.3% | Dec 12, 2024 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2024-10517 | MEDIUM | 4.8 | 0.3% | Dec 12, 2024 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2024-10010 | MEDIUM | 4.8 | 0.4% | Dec 12, 2024 | The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-12526 | MEDIUM | 4.3 | 0.2% | Dec 12, 2024 | The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Cross-Site Request Forgery in al... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now