2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12444MEDIUM5.4The WP Dispensary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpd_menu' shortcod...
CVE-2024-12320MEDIUM6.1The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all ver...
CVE-2024-12299MEDIUM6.1The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in ...
CVE-2024-12269HIGH7.5The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
CVE-2024-12177MEDIUM6.1The Ai Image Alt Text Generator for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pag...
CVE-2024-12129HIGH8.8The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escala...
CVE-2024-12102MEDIUM4.3The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 vi...
CVE-2024-11600HIGH7.2The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t...
CVE-2024-11583MEDIUM4.3The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t...
CVE-2024-10847MEDIUM5.4The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all version...
CVE-2024-10591HIGH8.8The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for Word...
CVE-2024-13466MEDIUM6.4The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2024-13380MEDIUM6.4The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2024-13706MEDIUM6.1The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in a...
CVE-2024-13453HIGH7.3The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcod...
CVE-2024-12524MEDIUM6.4The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-lo...
CVE-2024-12409MEDIUM6.1The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all...
CVE-2024-13758MEDIUM6.5The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2024-13732MEDIUM5.4The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2024-13694HIGH7.5The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is...
CVE-2024-13470MEDIUM5.4The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-13642MEDIUM5.4The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image...
CVE-2024-13457MEDIUM5.3The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version...
CVE-2024-12921MEDIUM6.4The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcod...
CVE-2024-12709MEDIUM4.3The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to m...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now