2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9705MEDIUM4.3The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2024-12155CRITICAL9.8The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e...
CVE-2024-12110MEDIUM4.3The Gold Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2024-12060MEDIUM6.1The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-cs...
CVE-2024-12028MEDIUM5.3The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST ...
CVE-2024-12027MEDIUM4.3The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a m...
CVE-2024-12003MEDIUM6.1The WP System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1...
CVE-2024-11823MEDIUM6.1The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' sh...
CVE-2024-11687MEDIUM6.1The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-11450MEDIUM6.4The ONLYOFFICE Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice' shor...
CVE-2024-11444MEDIUM4.3The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2024-11368MEDIUM6.1The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit...
CVE-2024-11352MEDIUM6.4The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' short...
CVE-2024-11339MEDIUM6.4The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button'...
CVE-2024-11336MEDIUM6.1The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2024-11323HIGH8.8The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privil...
CVE-2024-11292MEDIUM5.3The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ...
CVE-2024-11276MEDIUM6.1The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to Reflected ...
CVE-2024-11204MEDIUM6.1The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url...
CVE-2024-10879MEDIUM6.1The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the u...
CVE-2024-10849MEDIUM6.4The NewsMash theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versio...
CVE-2024-10692MEDIUM4.3The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Informatio...
CVE-2024-10689MEDIUM4.3The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Information Exposure in...
CVE-2024-10320MEDIUM6.4The Cookielay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookielay shortcode in ...
CVE-2024-11178HIGH8.1The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now