CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-37435

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in raratheme Perfect Portfolio perfect-portfolio allows Cross Site Request Forgery.This issue affects Perfect Portfolio: from n/a through <= 1.2.0.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37431

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in extendthemes Mesmerize mesmerize allows Cross Site Request Forgery.This issue affects Mesmerize: from n/a through <= 1.6.120.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37426

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in raratheme Elegant Pink elegant-pink allows Cross Site Request Forgery.This issue affects Elegant Pink: from n/a through <= 1.3.0.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37421

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in raratheme JobScout jobscout allows Cross Site Request Forgery.This issue affects JobScout: from n/a through <= 1.1.4.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37417

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This issue affects Coachify: from n/a through <= 1.0.7.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37413

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in raratheme Preschool and Kindergarten preschool-and-kindergarten allows Cross Site Request Forgery.This issue affects Preschool and Kindergarten: from n/a through <= 1.2.1.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37412

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Blossom Shop blossom-shop allows Cross Site Request Forgery.This issue affects Blossom Shop: from n/a through <= 1.1.7.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37274

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Rui Guerreiro WP Mobile Menu mobile-menu allows Cross Site Request Forgery.This issue affects WP Mobile Menu: from n/a through <= 2.8.4.3.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37272

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wptravelengine Travel Monster travel-monster allows Cross Site Request Forgery.This issue affects Travel Monster: from n/a through <= 1.1.2.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37243

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Vandana Lite vandana-lite allows Cross Site Request Forgery.This issue affects Vandana Lite: from n/a through <= 1.1.9.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37242

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Automattic Newspack Newsletters newspack-newsletters allows Cross Site Request Forgery.This issue affects Newspack Newsletters: from n/a through <= 2.13.2.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37240

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in sbouey Falang multilanguage falang allows Cross Site Request Forgery.This issue affects Falang multilanguage: from n/a through <= 1.3.51.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37238

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Greg Winiarski WPAdverts wpadverts allows Cross Site Request Forgery.This issue affects WPAdverts: from n/a through <= 2.1.2.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37236

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tim W Loco Translate loco-translate allows Cross Site Request Forgery.This issue affects Loco Translate: from n/a through <= 2.6.9.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37235

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Adrian Tobey Groundhogg groundhogg allows Cross Site Request Forgery.This issue affects Groundhogg: from n/a through <= 3.4.2.3.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37104

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in raratheme Chic Lite chic-lite allows Cross Site Request Forgery.This issue affects Chic Lite: from n/a through <= 1.1.3.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37103

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in raratheme Education Zone education-zone allows Cross Site Request Forgery.This issue affects Education Zone: from n/a through <= 1.3.4.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37102

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Vilva vilva allows Cross Site Request Forgery.This issue affects Vilva: from n/a through <= 1.2.2.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2024-37093

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through <= 3.2.1.

    Published: 2 Jan 2025
    7.5
    High

    CVE-2023-47693

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through <= 3.2.6.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-47692

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in flothemesplugins Flo Forms flo-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flo Forms: from n/a through <= 1.0.41.

    Published: 2 Jan 2025
    6.5
    Medium

    CVE-2023-47689

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Toast Plugins Animator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animator: from n/a through 3.0.10.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2023-47661

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Dragfy Dragfy Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dragfy Addons for Elementor: from n/a through 1.0.2.

    Published: 2 Jan 2025
    7.5
    High

    CVE-2023-47648

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Spider Themes EazyDocs eazydocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through <= 2.3.5.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-47647

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in LearningTimes BadgeOS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BadgeOS: from n/a through 3.7.1.6.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-47557

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in wp-buy Visitors Traffic Real Time Statistics visitors-traffic-real-time-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visitors Traffic Real Time Statistics: from n/a through <= 7.2.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-47523

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Ecreate Infotech Auto Tag Creator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Tag Creator: from n/a through 1.0.2.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-47515

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Seers Seers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seers: from n/a through 8.1.1.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-47241

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in CoCart Headless CoCart – Headless ecommerce cart-rest-api-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoCart – Headless ecommerce: from n/a through <= 3.11.2.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2023-47225

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in KaizenCoders Short URL shorten-url allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Short URL: from n/a through <= 1.6.8.

    Published: 2 Jan 2025
    7.5
    High

    CVE-2023-47224

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 7.8.0.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-47188

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in PressTigers Simple Job Board simple-job-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through <= 2.10.5.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2023-47187

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Labib Ahmed Animated Rotating Words css3-rotating-words allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animated Rotating Words: from n/a through <= 5.4.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-47183

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 2.33.1.

    Published: 2 Jan 2025
    6.5
    Medium

    CVE-2023-47180

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in XLPlugins Finale Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Finale Lite: from n/a through 2.16.0.

    Published: 2 Jan 2025
    8.8
    High

    CVE-2023-47179

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooODT Lite: from n/a through <= 2.4.6.

    Published: 2 Jan 2025
    6.5
    Medium

    CVE-2023-46644

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP CTA PRO WordPress CTA allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress CTA: from n/a through 1.5.8.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46639

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in FeedbackWP kk Star Ratings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects kk Star Ratings: from n/a through 5.4.5.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46637

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Saurav Sharma Generate Dummy Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Generate Dummy Posts: from n/a through 1.0.0.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46635

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Add-Ons: from n/a through <= 4.2.0.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2023-46633

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in TCBarrett Glossary allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Glossary: from n/a through 3.1.2.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2023-46632

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in David Cramer My Shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Shortcodes: from n/a through 2.3.

    Published: 2 Jan 2025
    6.5
    Medium

    CVE-2023-46631

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in RevenueHunt Product Recommendation Quiz for eCommerce product-recommendation-quiz-for-ecommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Recommendation Quiz for eCommerce: from n/a through <= 2.1.2.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-46628

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in RedLettuce Plugins WP Word Count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Word Count: from n/a through 3.2.4.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2023-46616

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in NSquared Draw Attention allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Draw Attention: from n/a through 2.0.15.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-46612

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in codedraft Mediabay mediabay-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mediabay: from n/a through <= 1.6.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46611

    Last Modified: 28 Apr 2026

    Authentication Bypass by Primary Weakness vulnerability in yourownprogrammer YOP Poll allows Authentication Bypass.This issue affects YOP Poll: from n/a through 6.5.28.

    Published: 2 Jan 2025
    6.5
    Medium

    CVE-2023-46610

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Mohamed Magdy Quill Forms quillforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quill Forms: from n/a through <= 3.3.0.

    Published: 2 Jan 2025
    6.5
    Medium

    CVE-2023-46609

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in FeedFocal FeedFocal feedfocal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FeedFocal: from n/a through <= 1.2.2.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46608

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in WPDO DoLogin Security dologin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DoLogin Security: from n/a through <= 3.7.1.

    Published: 2 Jan 2025