CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2024-39650

    Last Modified: 26 Jan 2026

    Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouchers: from n/a through 4.9.4.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-39654

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.12.

    Published: 1 Nov 2024
    7.3
    High

    CVE-2024-39664

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in YMC Filter & Grids allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Filter & Grids: from n/a through 2.8.33.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43118

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43119

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Aruba.It Aruba HiSpeed Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.12.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-43120

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in XSERVER Inc. TypeSquare Webfonts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects TypeSquare Webfonts: from n/a through 2.0.7.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43122

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Creative Motion Robin image optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robin image optimizer: from n/a through 1.6.9.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43134

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in xootix Waitlist Woocommerce ( Back in stock notifier ) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Waitlist Woocommerce ( Back in stock notifier ): from n/a through 2.6.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43136

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.1.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43142

    Last Modified: 4 Apr 2025

    Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through 2.7.3.

    Published: 1 Nov 2024
    6.4
    Medium

    CVE-2024-43143

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1.

    Published: 1 Nov 2024
    6.3
    Medium

    CVE-2024-43146

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Ahmed Kaludi, Mohammed Kaludi AMP for WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AMP for WP: from n/a through 1.0.96.1.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43154

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in BracketSpace Advanced Cron Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.9.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43157

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.10.

    Published: 1 Nov 2024
    7.5
    High

    CVE-2024-43158

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-43159

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.6.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43162

    Last Modified: 7 Feb 2025

    Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.2.12.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43208

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Matt Miller Send Emails with Mandrill send-emails-with-mandrill allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Send Emails with Mandrill: from n/a through <= 1.4.1.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43209

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Bitly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bitly: from n/a through 2.7.2.

    Published: 1 Nov 2024
    5.9
    Medium

    CVE-2024-43211

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps MailChimp Subscribe Forms allows Stored XSS.This issue affects MailChimp Subscribe Forms : from n/a through 4.0.9.9.

    Published: 1 Nov 2024
    7.5
    High

    CVE-2024-43212

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.7.7.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43215

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-43219

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in ووکامرس فارسی Persian WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Persian WooCommerce: from n/a through 7.1.6.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43223

    Last Modified: 12 Aug 2025

    Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.0.3.2.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43229

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Cornel Raiu WP Search Analytics search-analytics.This issue affects WP Search Analytics: from n/a through <= 1.4.9.

    Published: 1 Nov 2024
    7.1
    High

    CVE-2024-43235

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in MetaBox.Io Meta Box – WordPress Custom Fields Framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta Box – WordPress Custom Fields Framework: from n/a through 5.9.10.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-43253

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43254

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-43260

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Creative Motion Clearfy Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clearfy Cache: from n/a through 2.2.4.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-43268

    Last Modified: 15 Apr 2026

    Access Control vulnerability in WPBackItUp Backup and Restore WordPress allows . This issue affects Backup and Restore WordPress: from n/a through 1.50.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-43270

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in WPBackItUp Backup and Restore WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Backup and Restore WordPress: from n/a through 1.50.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-43273

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in icegram Icegram Collect plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Icegram Collect plugin: from n/a through 1.3.14.

    Published: 1 Nov 2024
    5.8
    Medium

    CVE-2024-43274

    Last Modified: 26 Jan 2026

    Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.6.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-43277

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in AyeCode Ltd UsersWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.15.

    Published: 1 Nov 2024
    6.3
    Medium

    CVE-2024-43285

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Presto Made, Inc Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Presto Player: from n/a through 3.0.2.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-43290

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration.This issue affects Atarim: from n/a through <= 4.0.1.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43293

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Recipe Card Blocks for Gutenberg & Elementor: from n/a through 3.3.1.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43296

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in bPlugins LLC Flash & HTML5 Video allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flash & HTML5 Video: from n/a through 2.5.30.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43297

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43298

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43302

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in Fonts Plugin Fonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fonts: from n/a through 3.7.7.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43310

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in UkrSolution Print Barcode Labels for your WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Barcode Labels for your WooCommerce products/orders: from n/a through 3.4.9.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-43312

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.1.9.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43314

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset CleanUp: Page Speed Booster: from n/a through 1.3.9.3.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-43323

    Last Modified: 19 Nov 2024

    Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43332

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in Jordy Meow Photo Engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Engine: from n/a through 6.4.0.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43341

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in CozyThemes Hello Agency allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hello Agency: from n/a through 1.0.5.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43343

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43355

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in BearDev JoomSport allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JoomSport: from n/a through 5.3.0.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-43919

    Last Modified: 13 Nov 2024

    Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.

    Published: 1 Nov 2024