2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1852MEDIUM6.1The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-F...
CVE-2024-1850MEDIUM6.3The AI Post Generator | AutoWriter plugin for WordPress is vulnerable to unauthorized access, modification or deletion o...
CVE-2024-1794MEDIUM6.1The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) i...
CVE-2024-1790MEDIUM4.9The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up t...
CVE-2024-1641MEDIUM5.4The Accordion plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missin...
CVE-2024-1637MEDIUM4.3The 360 Javascript Viewer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2024-1587MEDIUM5.3The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ...
CVE-2024-1571MEDIUM4.8The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in a...
CVE-2024-1498MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo ...
CVE-2024-1466MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_style...
CVE-2024-1465MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘carousel_ski...
CVE-2024-1464MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attri...
CVE-2024-1463MEDIUM4.8The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, ...
CVE-2024-1461MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attri...
CVE-2024-1458MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text_alignme...
CVE-2024-1424MEDIUM5.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-1412MEDIUM6.1The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' param...
CVE-2024-1387MEDIUM4.3The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient aut...
CVE-2024-1352MEDIUM5.3The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized a...
CVE-2024-1289MEDIUM5.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all vers...
CVE-2024-0899MEDIUM5.3The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscri...
CVE-2024-0873MEDIUM5.4The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shor...
CVE-2024-0872MEDIUM4.3The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-0826MEDIUM5.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets i...
CVE-2024-0662MEDIUM4.8The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now