CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2024-56046

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through <= 1.9.9.

    Published: 31 Dec 2024
    7.5
    High

    CVE-2024-56068

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-55991

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CRM System: from n/a through <= 3.2.9.1.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56031

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Yulio Aleman Jimenez Smart Shopify Product smart-shopify-product allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Shopify Product: from n/a through <= 1.0.2.

    Published: 31 Dec 2024
    7.5
    High

    CVE-2024-56067

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2023-48775

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Gfazioli WP Cleanfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cleanfix: from n/a through 5.6.2.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2023-50850

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Woo WooCommerce Subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Subscriptions: from n/a before 5.8.0.

    Published: 31 Dec 2024
    9.8
    Critical

    CVE-2024-56071

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in mikeleembruggen Simple Dashboard simple-dashboard allows Privilege Escalation.This issue affects Simple Dashboard: from n/a through <= 2.0.

    Published: 31 Dec 2024
    9.8
    Critical

    CVE-2024-56205

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in SunnyKai AI Magic newsletter-page-redirects allows Privilege Escalation.This issue affects AI Magic: from n/a through <= 1.0.4.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13074

    Last Modified: 3 Apr 2025

    A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    9.8
    Critical

    CVE-2024-13061

    Last Modified: 15 Apr 2026

    The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13072

    Last Modified: 6 Jan 2025

    A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add-customer-services.php of the component Customer Detail Handler. The manipulation of the argument sids[] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    7.1
    High

    CVE-2024-56209

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen Kleo kleo allows Reflected XSS.This issue affects Kleo: from n/a through < 5.4.4.

    Published: 31 Dec 2024
    7.1
    High

    CVE-2024-56210

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Userpro userpro allows Reflected XSS.This issue affects Userpro: from n/a through <= 5.1.9.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56221

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elicus WPMozo Addons Lite for Elementor wpmozo-addons-lite-for-elementor allows Stored XSS.This issue affects WPMozo Addons Lite for Elementor: from n/a through <= 1.2.0.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13070

    Last Modified: 3 Apr 2025

    A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/update_users.php of the component Update User Page. The manipulation of the argument user_upd leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    7.1
    High

    CVE-2024-56223

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood Gulri Slider gulri-slider allows Reflected XSS.This issue affects Gulri Slider: from n/a through <= 3.5.8.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56224

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ledenbeheer Ledenbeheer ledenbeheer-external-connection allows Stored XSS.This issue affects Ledenbeheer: from n/a through <= 2.1.0.

    Published: 31 Dec 2024
    7.1
    High

    CVE-2024-56226

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Reflected XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1001.

    Published: 31 Dec 2024
    7.1
    High

    CVE-2024-56228

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce.This issue affects Wishlist for WooCommerce: from n/a through <= 3.1.2.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56231

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio SaasPricing saaspricing allows DOM-Based XSS.This issue affects SaasPricing: from n/a through <= 1.2.4.

    Published: 31 Dec 2024
    7.1
    High

    CVE-2024-56233

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kinhelios KinTPV WooConnect kintpv-connect allows Stored XSS.This issue affects KinTPV WooConnect: from n/a through <= 8.129.

    Published: 31 Dec 2024
    5.4
    Medium

    CVE-2024-56234

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in vowelweb VW Automobile Lite vw-automobile-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Automobile Lite: from n/a through <= 2.1.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2024-56227

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1001.

    Published: 31 Dec 2024
    5.4
    Medium

    CVE-2024-56225

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.56.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2024-56219

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Marketing Fire Widget Options widget-options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through <= 4.0.6.1.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2024-56217

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.03.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2024-56215

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in DBAR Productions Member Directory and Contact Form pta-member-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Member Directory and Contact Form: from n/a through <= 1.7.0.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56235

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vicky Kumar Coupon coupon-lite allows DOM-Based XSS.This issue affects Coupon: from n/a through <= 1.2.2.

    Published: 31 Dec 2024
    5.9
    Medium

    CVE-2024-56256

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer.This issue affects Embed PDF Viewer: from n/a through <= 2.3.1.

    Published: 31 Dec 2024
    7.1
    High

    CVE-2024-56265

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2024-56218

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension allows Cross Site Request Forgery.This issue affects Contact Form 7 – Dynamic Text Extension: from n/a through <= 5.0.1.

    Published: 31 Dec 2024
    5.4
    Medium

    CVE-2024-56222

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Request Forgery.This issue affects CodeBard Help Desk: from n/a through <= 1.1.1.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2024-56229

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a through <= 4.6.

    Published: 31 Dec 2024
    7.1
    High

    CVE-2024-56232

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Alex Volkov WP Nice Loader wp-nice-loader allows Stored XSS.This issue affects WP Nice Loader: from n/a through <= 0.1.0.4.

    Published: 31 Dec 2024
    9.8
    Critical

    CVE-2024-56220

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through <= 3.6.0.

    Published: 31 Dec 2024
    8.5
    High

    CVE-2024-56212

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.9.

    Published: 31 Dec 2024
    8.8
    High

    CVE-2024-56211

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.9.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56213

    Last Modified: 23 Apr 2026

    Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.7.

    Published: 31 Dec 2024
    8.3
    High

    CVE-2024-56214

    Last Modified: 23 Apr 2026

    Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userpro: from n/a through <= 5.1.9.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56216

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Builder themify-builder allows PHP Local File Inclusion.This issue affects Themify Builder: from n/a through <= 7.6.3.

    Published: 31 Dec 2024
    7.5
    High

    CVE-2024-56230

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Maidul Dynamic Product Category Grid, Slider for WooCommerce dynamic-product-categories-design allows PHP Local File Inclusion.This issue affects Dynamic Product Category Grid, Slider for WooCommerce: from n/a through <= 1.1.3.

    Published: 31 Dec 2024
    5.2
    Medium

    CVE-2024-49422

    Last Modified: 2 Feb 2026

    Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13069

    Last Modified: 29 Apr 2025

    A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected is an unknown function of the file /endpoint/add-user.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-12105

    Last Modified: 8 Jan 2025

    In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.

    Published: 31 Dec 2024
    9.4
    Critical

    CVE-2024-12106

    Last Modified: 6 Jan 2025

    In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

    Published: 31 Dec 2024
    9.6
    Critical

    CVE-2024-12108

    Last Modified: 6 Jan 2025

    In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

    Published: 31 Dec 2024
    6.9
    Medium

    CVE-2024-13067

    Last Modified: 3 Apr 2025

    A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/all_users.php of the component All Users Page. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    9.8
    Critical

    CVE-2024-11972

    Last Modified: 17 May 2025

    The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Companion WordPress plugin before 1.9.0 from the WordPress.org repo, including vulnerable Hunk Companion WordPress plugin before 1.9.0 that have been closed.

    Published: 31 Dec 2024
    8.8
    High

    CVE-2024-13040

    Last Modified: 15 Apr 2026

    The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.

    Published: 31 Dec 2024