2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12255MEDIUM5.3The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versio...
CVE-2024-12172HIGH7.5The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress...
CVE-2024-12072MEDIUM6.1The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due ...
CVE-2024-12059MEDIUM4.3The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers...
CVE-2024-12040HIGH8.8The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion i...
CVE-2024-12018MEDIUM4.3The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorizatio...
CVE-2024-11882MEDIUM6.4The FAQ And Answers – Create Frequently Asked Questions Area on WP Sites plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-11871MEDIUM6.4The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'patreon'...
CVE-2024-11785MEDIUM6.4The Integrate Firebase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'firebase_show...
CVE-2024-11781MEDIUM6.4The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2024-11766MEDIUM6.4The WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more plugin for WordPress is vuln...
CVE-2024-11765MEDIUM6.4The WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more plugin for Wor...
CVE-2024-11757MEDIUM6.4The WP GeoNames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-geonames' shortco...
CVE-2024-11359MEDIUM6.1The Library Bookshelves plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-11052MEDIUM6.1The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-10637MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.54 does not validate and escape some of its bloc...
CVE-2024-10568MEDIUM4.7The Ajax Search Lite WordPress plugin before 4.12.4 does not sanitise and escape some of its settings, which could allo...
CVE-2024-10518MEDIUM4.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-10517MEDIUM4.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-10499HIGH7.2The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint b...
CVE-2024-10124CRITICAL9.8The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitr...
CVE-2024-10010MEDIUM4.8The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-12526MEDIUM4.3The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Cross-Site Request Forgery in al...
CVE-2024-12463MEDIUM5.4The Arena.IM – Live Blogging for real-time events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-12441MEDIUM6.1The BP Email Assign Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now