2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11810MEDIUM6.1The PayGreen Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message_id' p...
CVE-2024-11690MEDIUM6.1The Financial Stocks & Crypto Market Data Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2024-11496MEDIUM6.5The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2024-11465HIGH7.2The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to...
CVE-2024-11445MEDIUM6.4The Image Magnify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_magnify' sho...
CVE-2024-11434MEDIUM6.1The WP – Bulk SMS – by SMS.to plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame...
CVE-2024-11383MEDIUM6.4The CC Canadian Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '...
CVE-2024-11382MEDIUM6.4The Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites plugin for WordPress is ...
CVE-2024-11378MEDIUM6.1The Bizapp for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error' paramete...
CVE-2024-11377MEDIUM6.1The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par...
CVE-2024-11375MEDIUM6.1The WC1C plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ap...
CVE-2024-11363MEDIUM6.1The Same but Different – Related Posts by Taxonomy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2024-11338MEDIUM6.4The PIXNET Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtm' and 'venue' parameters...
CVE-2024-11337MEDIUM6.4The Horoscope And Tarot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'divine_horos...
CVE-2024-11290MEDIUM5.3The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2024-10527LOW3.1The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mo...
CVE-2024-12592MEDIUM6.4The Sellsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testSellsy' shortcode in ...
CVE-2024-12590MEDIUM6.4The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all v...
CVE-2024-12559MEDIUM5.3The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2024-12557MEDIUM6.1The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2024-12541MEDIUM5.4The Chative Live chat and Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2024-12540——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54288. Reason: This candidate is a ...
CVE-2024-12538MEDIUM4.3The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2024-12528MEDIUM6.4The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-12419MEDIUM6.5The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitrar...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now