2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10508CRITICAL9.8The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to pr...
CVE-2024-9874HIGH7.2The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injecti...
CVE-2024-10876MEDIUM6.1The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2024-10688MEDIUM4.3The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2 ...
CVE-2024-10683MEDIUM6.1The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to ...
CVE-2024-8756MEDIUM5.3The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
CVE-2024-10470CRITICAL9.8The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file re...
CVE-2024-10814MEDIUM6.4The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2...
CVE-2024-10770MEDIUM4.3The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 vi...
CVE-2024-10669MEDIUM4.3The Countdown Timer block – Display the event's date into a timer. plugin for WordPress is vulnerable to Informatio...
CVE-2024-10667MEDIUM4.3The Content Slider Block plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including...
CVE-2024-9226MEDIUM6.1The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Reflecte...
CVE-2024-10693MEDIUM4.3The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu...
CVE-2024-10674HIGH8.8The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capab...
CVE-2024-10673HIGH8.8The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capabilit...
CVE-2024-10627CRITICAL9.8The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t...
CVE-2024-10626HIGH8.1The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient ...
CVE-2024-10625CRITICAL9.1The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient ...
CVE-2024-9775MEDIUM4.8The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin se...
CVE-2024-9270MEDIUM6.4The Lenxel Core for Lenxel(LNX) LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploa...
CVE-2024-9262MEDIUM6.5The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Ob...
CVE-2024-8960MEDIUM5.4The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ...
CVE-2024-10779MEDIUM4.3The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-10588MEDIUM4.3The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th...
CVE-2024-10586CRITICAL9.8The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the db...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now