2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10614MEDIUM4.3The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili...
CVE-2024-8856CRITICAL9.8The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi...
CVE-2024-10728HIGH8.8The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plug...
CVE-2024-9938MEDIUM6.1The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame...
CVE-2024-9935HIGH7.5The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions ...
CVE-2024-9850MEDIUM6.4The SVG Case Study plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all version...
CVE-2024-9849HIGH8.8The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file up...
CVE-2024-9839HIGH7.3The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc...
CVE-2024-9615MEDIUM6.1The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho...
CVE-2024-9386MEDIUM6.4The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-9192HIGH8.8The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due t...
CVE-2024-8873MEDIUM6.1The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th...
CVE-2024-6628MEDIUM4.3The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site R...
CVE-2024-11118MEDIUM5.3The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-11092MEDIUM6.4The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versi...
CVE-2024-11085MEDIUM5.4The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability ch...
CVE-2024-10884MEDIUM6.1The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-10883MEDIUM6.1The SimpleForm – Contact form made simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th...
CVE-2024-10875MEDIUM6.1The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_...
CVE-2024-10533MEDIUM4.3The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check...
CVE-2024-10262MEDIUM6.3The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and...
CVE-2024-10147MEDIUM6.4The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versio...
CVE-2024-10017MEDIUM6.4The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-10015MEDIUM6.4The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and '...
CVE-2024-10861MEDIUM5.3The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now