2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10866MEDIUM5.3The Export Import Menus plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch...
CVE-2024-9502MEDIUM5.4The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ...
CVE-2024-9354MEDIUM6.1The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'color' par...
CVE-2024-12781MEDIUM4.3The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of dat...
CVE-2024-12624MEDIUM5.4The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina...
CVE-2024-12499MEDIUM6.4The WP jQuery DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_jdt' shor...
CVE-2024-12495MEDIUM6.4The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-boo...
CVE-2024-12437MEDIUM6.4The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'envato' shortc...
CVE-2024-11764MEDIUM6.4The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'solar_wizard' ...
CVE-2024-11725HIGH8.8The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data ...
CVE-2024-11282HIGH7.5The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure i...
CVE-2024-9702MEDIUM5.4The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-9697MEDIUM5.3The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2024-9638MEDIUM4.8The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could ...
CVE-2024-8857MEDIUM4.8The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could...
CVE-2024-8855CRITICAL9.8The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a ...
CVE-2024-7696MEDIUM6.3Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated mal...
CVE-2024-12849HIGH7.5The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inc...
CVE-2024-12633HIGH7.1The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross...
CVE-2024-12535HIGH8.6The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check wh...
CVE-2024-12471HIGH8.8The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is...
CVE-2024-12464MEDIUM6.4The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' sho...
CVE-2024-12440MEDIUM6.4The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in ...
CVE-2024-12439MEDIUM6.4The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' s...
CVE-2024-12438MEDIUM6.1The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now