2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11424MEDIUM6.4The Slick Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slick-sitemap' sho...
CVE-2024-11416MEDIUM6.1The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-11414MEDIUM6.4The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all...
CVE-2024-11412MEDIUM6.4The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shor...
CVE-2024-11409HIGH7.2The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1...
CVE-2024-11388MEDIUM5.4The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-11385MEDIUM5.4The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cir...
CVE-2024-11371MEDIUM6.1The Theater for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que...
CVE-2024-11370MEDIUM6.1The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a...
CVE-2024-11365MEDIUM6.1The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-11360MEDIUM6.1The Page Parts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg w...
CVE-2024-11354MEDIUM4.3The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2024-11334MEDIUM5.3The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2024-11320CRITICAL9.8Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication me...
CVE-2024-11197MEDIUM4.2The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5...
CVE-2024-10898HIGH8.8The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2024-10890MEDIUM6.1The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...
CVE-2024-10796MEDIUM4.3The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up ...
CVE-2024-10792MEDIUM6.1The Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Reflected Cros...
CVE-2024-10788HIGH7.2The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2024-10785MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-10782MEDIUM4.3The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in...
CVE-2024-10726MEDIUM6.1The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2024-10696MEDIUM4.3The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere El...
CVE-2024-10682MEDIUM6.1The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting d...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now