2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12290MEDIUM6.1The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in...
CVE-2024-12288MEDIUM6.1The Simple add pages or posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-12264CRITICAL9.8The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ...
CVE-2024-12256MEDIUM6.1The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analyti...
CVE-2024-12252CRITICAL9.8The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remo...
CVE-2024-12214MEDIUM6.1The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v...
CVE-2024-12208Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-43269. Reason: This candidate is a ...
CVE-2024-12207MEDIUM4.4The Toggles Shortcode and Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ par...
CVE-2024-12176MEDIUM5.3The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capabi...
CVE-2024-12170MEDIUM5.4The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-12159MEDIUM5.3The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Inform...
CVE-2024-12158MEDIUM5.3The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to unauthorized l...
CVE-2024-12157HIGH7.5The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection ...
CVE-2024-12153MEDIUM6.1The GDY Modular Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-12140MEDIUM4.3The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to ...
CVE-2024-12126MEDIUM6.1The SEO Keywords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘google_error’ parameter i...
CVE-2024-12124Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54290. Reason: This candidate is a ...
CVE-2024-12049MEDIUM6.1The Woo Ukrposhta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order', 'post', and 'idd...
CVE-2024-11810MEDIUM6.1The PayGreen Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message_id' p...
CVE-2024-11690MEDIUM6.1The Financial Stocks & Crypto Market Data Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2024-11496MEDIUM6.5The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2024-11465HIGH7.2The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...
CVE-2024-11445MEDIUM6.4The Image Magnify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_magnify' sho...
CVE-2024-11434MEDIUM6.1The WP – Bulk SMS – by SMS.to plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame...
CVE-2024-11383MEDIUM6.4The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now