CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-46607

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP iCal Availability WP iCal Availability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP iCal Availability: from n/a through 1.0.3.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46606

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Team AtomChat AtomChat atomchat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AtomChat: from n/a through <= 1.1.4.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46605

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Ruslan Suhar Convertful – Your Ultimate On-Site Conversion Tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Convertful – Your Ultimate On-Site Conversion Tool: from n/a through 2.5.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46309

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.10.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46206

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Webの相談所 MW WP Form mw-wp-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MW WP Form: from n/a through <= 4.4.5.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-46203

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in JustCoded / Alex Prokopenko Just Custom Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Just Custom Fields: from n/a through 3.3.2.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-46196

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social proof testimonials and reviews by Repuso: from n/a through <= 4.97.

    Published: 2 Jan 2025
    6.5
    Medium

    CVE-2023-46195

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in CoSchedule Headline Analyzer headline-analyzer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Headline Analyzer: from n/a through <= 1.3.1.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-46188

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Jose Mortellaro Freesoul Deactivate Plugins – Plugin manager and cleanup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Freesoul Deactivate Plugins – Plugin manager and cleanup: from n/a through 2.1.3.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46083

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.27.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46082

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Cyberlord92 Broken Link Checker | Finder broken-link-finder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Checker | Finder: from n/a through <= 2.4.2.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-46080

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline – Application Form Builder and Manager: from n/a through 2.5.3.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2023-46079

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP Royal Ashe Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe Extra: from n/a through 1.2.9.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-46073

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Mario Peshev DX Delete Attached Media dx-delete-attached-media allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DX Delete Attached Media: from n/a through <= 2.0.5.1.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2023-45828

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in RumbleTalk RumbleTalk Live Group Chat rumbletalk-chat-a-chat-with-themes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RumbleTalk Live Group Chat: from n/a through <= 6.2.5.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-45766

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through <= 4.7.1.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-45765

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.12.6.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-45760

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.3.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-45649

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in codepeople Appointment Hour Booking appointment-hour-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Appointment Hour Booking: from n/a through <= 1.4.23.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2023-45636

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Backup & Migration: from n/a through <= 1.4.1.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-45631

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

    Published: 2 Jan 2025
    6.5
    Medium

    CVE-2023-45275

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.28.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-45271

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in WPXPO WowStore product-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowStore: from n/a through <= 2.7.8.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-45110

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in boldthemes Bold Timeline Lite bold-timeline-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bold Timeline Lite: from n/a through <= 1.1.9.

    Published: 2 Jan 2025
    7.3
    High

    CVE-2023-45104

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in WPDeveloper BetterLinks betterlinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterLinks: from n/a through <= 1.6.0.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-45101

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce customer-reviews-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customer Reviews for WooCommerce: from n/a through <= 5.36.0.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-45061

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in awsm.in WP Job Openings wp-job-openings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Openings: from n/a through <= 3.4.1.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2023-45045

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in krozero WP Custom Widget area wp-custom-widget-area allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Widget area: from n/a through <= 1.2.5.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-45002

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through 3.6.8.

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2023-44988

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Martin Gibson WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.32.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2023-44258

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in vberkel Schema App Structured Data schema-app-structured-data-for-schemaorg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through <= 1.23.1.

    Published: 2 Jan 2025
    6.3
    Medium

    CVE-2024-13111

    Last Modified: 2 Jan 2025

    A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Handler. The manipulation leads to improper authentication. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2024-13110

    Last Modified: 2 Jan 2025

    A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56027

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bizswoop Leads CRM leads-crm allows Reflected XSS.This issue affects Leads CRM: from n/a through <= 2.0.13.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56028

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lemonadestudio Lemonade Social Networks Autoposter Pinterest lemonade-sna-pinterest-edition allows Reflected XSS.This issue affects Lemonade Social Networks Autoposter Pinterest: from n/a through <= 2.0.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56029

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dreamwinner Easy Language Switcher easy-language-switcher allows Reflected XSS.This issue affects Easy Language Switcher: from n/a through <= 1.0.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56030

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Carver Lab 10CentMail 10centmail-subscription-management-and-analytics allows Reflected XSS.This issue affects 10CentMail: from n/a through <= 2.1.50.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56032

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Descriptions fv-descriptions allows Reflected XSS.This issue affects FV Descriptions: from n/a through <= 1.4.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56033

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 FAQs faqs allows Reflected XSS.This issue affects FAQs: from n/a through <= 1.0.2.

    Published: 2 Jan 2025
    6.5
    Medium

    CVE-2024-56019

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gavinr Inline Footnotes inline-footnotes allows Stored XSS.This issue affects Inline Footnotes: from n/a through <= 2.3.0.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56034

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irshad A.Khan Services updates for customers service-updates-for-customers allows Reflected XSS.This issue affects Services updates for customers: from n/a through <= 1.0.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56035

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kurt Payne Upload Scanner upload-scanner allows Reflected XSS.This issue affects Upload Scanner: from n/a through <= 1.2.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56036

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ondrej Donek odPhotogallery od-photogallery-plugin allows Reflected XSS.This issue affects odPhotogallery: from n/a through <= 0.5.3.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56037

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftClever Limited User Referral user-referral-free allows Reflected XSS.This issue affects User Referral: from n/a through <= 8.0.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56038

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catalinsendsms SendSMS sendsms allows Reflected XSS.This issue affects SendSMS: from n/a through <= 1.2.9.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56060

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms html-forms allows Reflected XSS.This issue affects HTML Forms: from n/a through <= 1.4.1.

    Published: 2 Jan 2025
    7.1
    High

    CVE-2024-56069

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Reflected XSS.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

    Published: 2 Jan 2025
    7.2
    High

    CVE-2024-13062

    Last Modified: 15 Apr 2026

    An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

    Published: 2 Jan 2025
    7.2
    High

    CVE-2024-12912

    Last Modified: 15 Apr 2026

    An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

    Published: 2 Jan 2025
    6.9
    Medium

    CVE-2024-13109

    Last Modified: 2 Jan 2025

    A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025