2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5769MEDIUM4.3The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-12848HIGH8.8The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on t...
CVE-2024-12819MEDIUM6.4The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortc...
CVE-2024-12621MEDIUM6.4The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' ...
CVE-2024-12618MEDIUM4.3The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2024-12616MEDIUM4.3The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-12605MEDIUM4.3The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch...
CVE-2024-12542HIGH8.6The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when incl...
CVE-2024-12515MEDIUM6.4The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID ...
CVE-2024-12514MEDIUM6.4The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' short...
CVE-2024-12496MEDIUM6.4The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissi...
CVE-2024-12493MEDIUM6.4The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' sh...
CVE-2024-12491MEDIUM6.4The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_se...
CVE-2024-12394MEDIUM6.1The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all ...
CVE-2024-12330HIGH7.5The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensit...
CVE-2024-12285MEDIUM6.1The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versi...
CVE-2024-12249MEDIUM4.3The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-12222MEDIUM6.1The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvs...
CVE-2024-12218MEDIUM6.1The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2024-12206MEDIUM4.3The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2024-12122MEDIUM6.1The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions ...
CVE-2024-12067MEDIUM6.5The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injecti...
CVE-2024-11929MEDIUM6.4The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp...
CVE-2024-11907MEDIUM6.4The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_ifram...
CVE-2024-11815MEDIUM6.1The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now