2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9224MEDIUM6.5The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1...
CVE-2024-9220MEDIUM6.1The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_...
CVE-2024-9209MEDIUM6.1The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-9018HIGH8.8The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘k...
CVE-2024-8799MEDIUM6.1The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ...
CVE-2024-8793MEDIUM6.1The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress...
CVE-2024-8786MEDIUM6.1The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...
CVE-2024-8430MEDIUM5.3The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
CVE-2024-8324MEDIUM6.4The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all ver...
CVE-2024-8288MEDIUM6.4The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to S...
CVE-2024-9304MEDIUM6.4The LocateAndFilter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-9274MEDIUM6.4The Elastik Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v...
CVE-2024-9272MEDIUM6.4The R Animated Icon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all...
CVE-2024-9269MEDIUM6.4The Relogo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,...
CVE-2024-9267MEDIUM6.1The Easy WordPress Subscribe – Optin Hound plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t...
CVE-2024-9145HIGH7.1Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in ver...
CVE-2024-9119MEDIUM6.4The SVG Complete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ...
CVE-2024-9108CRITICAL9.8The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid...
CVE-2024-9106CRITICAL9.8The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1....
CVE-2024-8990MEDIUM6.4The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_pos...
CVE-2024-8989MEDIUM6.4The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress i...
CVE-2024-8728MEDIUM6.1The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ...
CVE-2024-8727MEDIUM6.1The DK PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ...
CVE-2024-8720MEDIUM6.4The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2024-8718MEDIUM6.1The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now