2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9635MEDIUM6.1The Checkout with Cash App on WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2024-11446MEDIUM6.1The Chessgame Shizzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cs_nonce' parameter ...
CVE-2024-11330MEDIUM6.1The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer...
CVE-2024-11265MEDIUM4.3The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosu...
CVE-2024-11188MEDIUM6.1The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for Word...
CVE-2024-11426MEDIUM6.4The AutoListicle: Automatically Update Numbered List Articles plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-11408MEDIUM6.4The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti' shortc...
CVE-2024-11387MEDIUM6.4The Easy Liveblogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elb_liveblog' sho...
CVE-2024-11361MEDIUM6.1The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Sc...
CVE-2024-11332MEDIUM6.4The HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents plugin for WordPress is vulnerable t...
CVE-2024-10880MEDIUM6.1The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
CVE-2024-10873HIGH8.8The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
CVE-2024-10606MEDIUM4.3The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-9223MEDIUM4.3The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on ...
CVE-2024-11463MEDIUM6.1The DeBounce Email Validator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from', 'to', ...
CVE-2024-11415HIGH8.8The WP-Orphanage Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-11362MEDIUM6.1The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v...
CVE-2024-10961CRITICAL9.8The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0...
CVE-2024-10886MEDIUM6.4The Tribute Testimonials – WordPress Testimonial Grid/Slider plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2024-10874MEDIUM6.4The Quotes llama plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quotes-llama' short...
CVE-2024-10869MEDIUM6.1The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-10868MEDIUM4.3The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in...
CVE-2024-10813HIGH7.5The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive...
CVE-2024-10537MEDIUM4.3The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of dat...
CVE-2024-10216MEDIUM4.3The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now