CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2023-38393

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

    Published: 19 Jun 2024
    5.4
    Medium

    CVE-2023-38394

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

    Published: 19 Jun 2024
    5.4
    Medium

    CVE-2023-39310

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.

    Published: 19 Jun 2024
    5.4
    Medium

    CVE-2023-36676

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.

    Published: 19 Jun 2024
    6.5
    Medium

    CVE-2023-36683

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in WP SCHEMA PRO Schema Pro.This issue affects Schema Pro: from n/a through 2.7.8.

    Published: 19 Jun 2024
    7.1
    High

    CVE-2023-36684

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7.5.

    Published: 19 Jun 2024
    6.5
    Medium

    CVE-2023-37869

    Last Modified: 23 Jan 2025

    Missing Authorization vulnerability in Premium Addons Premium Addons PRO.This issue affects Premium Addons PRO: from n/a through 2.9.0.

    Published: 19 Jun 2024
    6.5
    Medium

    CVE-2023-37872

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.5.

    Published: 19 Jun 2024
    7.7
    High

    CVE-2024-38329

    Last Modified: 21 Nov 2024

    IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a specially crafted request, an attacker could exploit this vulnerability to change its settings, trigger backups, restore backups, and also delete all previous backups via log rotation. IBM X-Force ID: 294994.

    Published: 19 Jun 2024
    7.6
    High

    CVE-2023-38386

    Last Modified: 7 Apr 2025

    Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.

    Published: 19 Jun 2024
    6.5
    Medium

    CVE-2023-36512

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Woo AutomateWoo.This issue affects AutomateWoo: from n/a through 5.7.5.

    Published: 19 Jun 2024
    8.1
    High

    CVE-2023-37870

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9.

    Published: 19 Jun 2024
    5.4
    Medium

    CVE-2023-35050

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0.

    Published: 19 Jun 2024
    7.5
    High

    CVE-2023-35049

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.

    Published: 19 Jun 2024
    6.5
    Medium

    CVE-2023-41805

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Brainstorm Force Premium Starter Templates, Brainstorm Force Starter Templates astra-sites.This issue affects Premium Starter Templates: from n/a through 3.2.5; Starter Templates: from n/a through 3.2.5.

    Published: 19 Jun 2024
    4.3
    Medium

    CVE-2023-39922

    Last Modified: 5 Feb 2025

    Missing Authorization vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

    Published: 19 Jun 2024
    5.4
    Medium

    CVE-2023-39990

    Last Modified: 24 Jan 2025

    Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.

    Published: 19 Jun 2024
    4.3
    Medium

    CVE-2023-39993

    Last Modified: 9 Apr 2025

    Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0.

    Published: 19 Jun 2024
    8.2
    High

    CVE-2023-39998

    Last Modified: 31 Jan 2025

    Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1.

    Published: 19 Jun 2024
    7.3
    High

    CVE-2023-40004

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This issue affects All-in-One WP Migration Box Extension: from n/a through 1.53; All-in-One WP Migration OneDrive Extension: from n/a through 1.66; All-in-One WP Migration Dropbox Extension: from n/a through 3.75; All-in-One WP Migration Google Drive Extension: from n/a through 2.79.

    Published: 19 Jun 2024
    8.2
    High

    CVE-2023-40608

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Paid Memberships Pro Paid Memberships Pro CCBill Gateway.This issue affects Paid Memberships Pro CCBill Gateway: from n/a through 0.3.

    Published: 19 Jun 2024
    5.4
    Medium

    CVE-2023-44148

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.

    Published: 19 Jun 2024
    5.4
    Medium

    CVE-2023-44151

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Brainstorm Force Pre-Publish Checklist.This issue affects Pre-Publish Checklist: from n/a through 1.1.1.

    Published: 19 Jun 2024
    7.6
    High

    CVE-2023-45658

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in POSIMYTH Nexter.This issue affects Nexter: from n/a through 2.0.3.

    Published: 19 Jun 2024
    8.3
    High

    CVE-2023-46146

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

    Published: 19 Jun 2024
    8.8
    High

    CVE-2023-46148

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

    Published: 19 Jun 2024
    7.6
    High

    CVE-2023-47770

    Last Modified: 9 Jun 2025

    Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.

    Published: 19 Jun 2024
    6.5
    Medium

    CVE-2023-47681

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in QuadLayers WooCommerce Checkout Manager.This issue affects WooCommerce Checkout Manager: from n/a through 7.3.0.

    Published: 19 Jun 2024
    8.3
    High

    CVE-2023-47771

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in ThemePunch OHG Essential Grid.This issue affects Essential Grid: from n/a through 3.0.18.

    Published: 19 Jun 2024
    8.3
    High

    CVE-2023-47783

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Thrive Themes Thrive Theme Builder.This issue affects Thrive Theme Builder: from n/a before 3.24.0.

    Published: 19 Jun 2024
    4.3
    Medium

    CVE-2023-47788

    Last Modified: 23 Jan 2026

    Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.

    Published: 19 Jun 2024
    7.5
    High

    CVE-2023-48759

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

    Published: 19 Jun 2024
    8.2
    High

    CVE-2023-48760

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

    Published: 19 Jun 2024
    6.3
    Medium

    CVE-2023-48761

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.

    Published: 19 Jun 2024
    6.5
    Medium

    CVE-2024-35765

    Last Modified: 9 Jun 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wpsoul Greenshift – animation and page builder blocks allows Stored XSS.This issue affects Greenshift – animation and page builder blocks: from n/a through 8.8.9.1.

    Published: 19 Jun 2024
    8.5
    High

    CVE-2024-35780

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.42.

    Published: 19 Jun 2024
    4.3
    Medium

    CVE-2023-50900

    Last Modified: 27 May 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.10.

    Published: 19 Jun 2024
    6.8
    Medium

    CVE-2024-5676

    Last Modified: 15 Apr 2026

    The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.

    Published: 19 Jun 2024
    6.4
    Medium

    CVE-2024-4632

    Last Modified: 15 Apr 2026

    The WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Jun 2024
    4.4
    Medium

    CVE-2023-6495

    Last Modified: 8 Apr 2026

    The YARPP – Yet Another Related Posts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 5.30.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 19 Jun 2024
    6.4
    Medium

    CVE-2024-0383

    Last Modified: 8 Apr 2026

    The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [wprm-recipe-instructions] and [wprm-recipe-ingredients] shortcodes in all versions up to, and including, 9.1.0 due to insufficient restrictions on the 'group_tag' attribute . This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Jun 2024
    5.3
    Medium

    CVE-2024-0789

    Last Modified: 15 Apr 2026

    The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass maintenance mode.

    Published: 19 Jun 2024
    5.4
    Medium

    CVE-2024-1407

    Last Modified: 8 Apr 2026

    The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to subscribe to, modify, or cancel membership for a user via a forged request granted they can trick a user into performing an action such as clicking on a link.

    Published: 19 Jun 2024
    6.4
    Medium

    CVE-2024-3894

    Last Modified: 15 Apr 2026

    The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an Image Title in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Jun 2024
    4
    Medium

    CVE-2024-37387

    Last Modified: 15 Apr 2026

    Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered.

    Published: 19 Jun 2024
    9.8
    Critical

    CVE-2024-37124

    Last Modified: 15 Apr 2026

    Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.

    Published: 19 Jun 2024
    9.8
    Critical

    CVE-2024-36480

    Last Modified: 15 Apr 2026

    Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the PC.

    Published: 19 Jun 2024
    6.3
    Medium

    CVE-2024-36252

    Last Modified: 15 Apr 2026

    Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed.

    Published: 19 Jun 2024
    5.3
    Medium

    CVE-2024-37881

    Last Modified: 15 Apr 2026

    SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from other URLs. However, SiteGuard WP Plugin versions prior to 1.7.7 missed to implement a measure to avoid redirection from wp-register.php. As a result, the customized path to the login page may be exposed.

    Published: 19 Jun 2024
    6.5
    Medium

    CVE-2024-5208

    Last Modified: 15 Oct 2025

    An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of service (DOS) by shutting down the server through sending invalid upload requests. Specifically, the server can be made to shut down by sending an empty body with a 'Content-Length: 0' header or by sending a body with arbitrary content, such as 'asdasdasd', with a 'Content-Length: 9' header. The vulnerability is reproducible by users with at least a 'Manager' role, sending a crafted request to any workspace. This issue indicates that a previous fix was not effective in mitigating the vulnerability.

    Published: 19 Jun 2024