2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6797MEDIUM4.8The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-6719HIGH8.1The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which co...
CVE-2024-6718MEDIUM5.4The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before o...
CVE-2024-6713MEDIUM4.8The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-6712MEDIUM6.1The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as...
CVE-2024-6711LOW3.5The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which ...
CVE-2024-6708MEDIUM4.8The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting ...
CVE-2024-6693MEDIUM4.8The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-6690MEDIUM6.1The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirectio...
CVE-2024-6668MEDIUM5.4The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access control...
CVE-2024-6667MEDIUM6.1The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outpu...
CVE-2024-6665MEDIUM4.8The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, wh...
CVE-2024-6584CRITICAL9.1The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.
CVE-2024-6486HIGH7.2The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injec...
CVE-2024-6478MEDIUM4.8The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, whic...
CVE-2024-6462MEDIUM4.8The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-6335MEDIUM4.8The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could a...
CVE-2024-6159CRITICAL9.8The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a para...
CVE-2024-5440MEDIUM5.4The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its short...
CVE-2024-5026MEDIUM4.8The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could all...
CVE-2024-4665MEDIUM6.4The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing use...
CVE-2024-4091LOW3.5The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which coul...
CVE-2024-4004LOW3.5The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could ...
CVE-2024-4002LOW3.5The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its set...
CVE-2024-3996LOW3.5The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now