2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8032MEDIUM6.1The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sani...
CVE-2024-8031MEDIUM6.5The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloade...
CVE-2024-8009MEDIUM4.3The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers ...
CVE-2024-7984MEDIUM4.3The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which...
CVE-2024-7769MEDIUM4.8The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-7762LOW3.7The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthen...
CVE-2024-7761MEDIUM6.1In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you...
CVE-2024-7759MEDIUM4.8The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-7758MEDIUM4.8The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could all...
CVE-2024-7556MEDIUM4.8The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-6809CRITICAL9.8The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using ...
CVE-2024-6798MEDIUM4.8The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow hi...
CVE-2024-6797MEDIUM4.8The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-6719HIGH8.1The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which co...
CVE-2024-6718MEDIUM5.4The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before o...
CVE-2024-6713MEDIUM4.8The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-6712MEDIUM6.1The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as...
CVE-2024-6711LOW3.5The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which ...
CVE-2024-6708MEDIUM4.8The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting ...
CVE-2024-6693MEDIUM4.8The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-6690MEDIUM6.1The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirectio...
CVE-2024-6668MEDIUM5.4The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access control...
CVE-2024-6667MEDIUM6.1The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outpu...
CVE-2024-6665MEDIUM4.8The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, wh...
CVE-2024-6584CRITICAL9.1The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now