CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-54231

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Order Export ni-woocommerce-order-export allows Reflected XSS.This issue affects Ni WooCommerce Order Export: from n/a through <= 3.1.6.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-44149

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brands for WooCommerce: from n/a through <= 3.8.2.2.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-44147

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in apasionados Comment Blacklist Updater comment-blacklist-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comment Blacklist Updater: from n/a through <= 1.1.0.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2023-44142

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Deepen Bajracharya Inactive Logout inactive-logout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Inactive Logout: from n/a through <= 3.2.2.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-41952

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Contact Form - WPManageNinja LLC FluentForm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through 5.0.8.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-41951

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-41875

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory Kit: from n/a through 1.2.6.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-41873

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in miniOrange SAML SP Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SAML SP Single Sign On: from n/a through 5.0.4.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-41870

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.5.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-41869

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.4.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-41866

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Team Plugins360 Automatic YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic YouTube Gallery: from n/a through 2.3.3.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-41865

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in bqworks Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Pro: from n/a through 4.8.6.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-41862

    Last Modified: 28 Apr 2026

    Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2023-41857

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ClickToTweet.com Click To Tweet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Click To Tweet: from n/a through 2.0.14.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-41849

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP Happy Coders Posts Like Dislike allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Posts Like Dislike: from n/a through 1.1.0.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-41848

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-41803

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in BitPay BitPay Checkout for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BitPay Checkout for WooCommerce: from n/a through 4.1.0.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-41802

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Team Heateor Super Socializer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Socializer: from n/a through 7.13.54.

    Published: 13 Dec 2024
    3.5
    Low

    CVE-2023-41695

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.1.0.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-41690

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Wiser Notify WiserNotify Social Proof allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserNotify Social Proof: from n/a through 2.5.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-41689

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Koen Reus Post to Google My Business (Google Business Profile) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post to Google My Business (Google Business Profile): from n/a through 3.1.14.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2023-41688

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 1.5.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2023-41686

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ilGhera Woocommerce Support System allows Cross Site Request Forgery.This issue affects Woocommerce Support System: from n/a through 1.2.2.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2023-41683

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Pechenki TelSender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TelSender: from n/a through 1.14.11.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2023-41671

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in tychesoftwares Abandoned Cart Lite for WooCommerce woocommerce-abandoned-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Abandoned Cart Lite for WooCommerce: from n/a through <= 5.16.1.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2023-41664

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in AlphaBPO Easy Newsletter Signups allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Newsletter Signups: from n/a through 1.0.4.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2023-41649

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Ovic Team Ovic Product Bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ovic Product Bundle: from n/a through 1.1.2.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-41133

    Last Modified: 28 Apr 2026

    Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-41132

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ShapedPlugin LLC Category Slider for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Category Slider for WooCommerce: from n/a through 1.4.15.

    Published: 13 Dec 2024
    8.1
    High

    CVE-2023-41130

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through <= 1.0.12.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2023-40678

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Andrew Fiebert Simple URLs simple-urls allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through <= 117.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-40670

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.17.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-40334

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in RealMag777 HUSKY woocommerce-products-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HUSKY: from n/a through <= 1.3.4.2.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-40331

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in bqworks Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider: from n/a through 1.9.6.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-40213

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Mateusz Czardybon Justified Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Justified Gallery: from n/a through 1.7.3.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-40203

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in MailMunch MailChimp Forms by MailMunch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailChimp Forms by MailMunch: from n/a through 3.1.4.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2023-40011

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in StylemixThemes Cost Calculator Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost Calculator Builder: from n/a through 3.1.42.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-40005

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Syed Balkhi Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through <= 3.1.5.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2023-40003

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through <= 2.6.7.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-40001

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in SolidWP iThemes Sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through 2.1.13.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-39997

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-39996

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Accordion and Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion and Accordion Slider: from n/a through 1.2.4.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-39995

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Portfolio and Projects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio and Projects: from n/a through 1.3.7.

    Published: 13 Dec 2024
    7.5
    High

    CVE-2023-39920

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Themeisle Redirection for Contact Form 7 wpcf7-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirection for Contact Form 7: from n/a through <= 2.9.2.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-39305

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Dash Labs Yet Another Stars Rating yet-another-stars-rating allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yet Another Stars Rating: from n/a through <= 3.4.3.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-38514

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2023-38483

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Dylan Blokhuis Instant CSS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Instant CSS: from n/a through 1.1.4.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-38480

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Certain Dev Booster Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster Elementor Addons: from n/a through 1.4.9.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-38479

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Codents Simple Googlebot Visit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Googlebot Visit: from n/a through 1.2.4.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-38477

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Stanislav Kuznetsov QR code MeCard/vCard generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QR code MeCard/vCard generator: from n/a through 1.6.0.

    Published: 13 Dec 2024