CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-45188

    Last Modified: 21 Nov 2024

    IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 268751.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2024-32824

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster.This issue affects Evergreen Content Poster: from n/a through <= 1.4.2.

    Published: 9 Jun 2024
    7.5
    High

    CVE-2024-33543

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-33545

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10.

    Published: 9 Jun 2024
    8.3
    High

    CVE-2024-33547

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10.

    Published: 9 Jun 2024
    8.1
    High

    CVE-2024-33555

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.

    Published: 9 Jun 2024
    7.5
    High

    CVE-2024-33561

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.

    Published: 9 Jun 2024
    7.6
    High

    CVE-2024-33563

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.

    Published: 9 Jun 2024
    8.8
    High

    CVE-2024-33564

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.

    Published: 9 Jun 2024
    9.1
    Critical

    CVE-2024-33565

    Last Modified: 26 Nov 2024

    Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-33572

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor.This issue affects Nexter Blocks: from n/a through <= 3.2.5.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-34435

    Last Modified: 26 Nov 2024

    Missing Authorization vulnerability in CodeRevolution Aiomatic.This issue affects Aiomatic: from n/a through 1.9.3.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2024-35660

    Last Modified: 26 Nov 2024

    Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-35669

    Last Modified: 26 Nov 2024

    Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-31274

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.11.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-31273

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.3.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-31267

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-31261

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Aakash Chakravarthy Announcer – Notification & message bars.This issue affects Announcer – Notification & message bars: from n/a through 6.0.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-31252

    Last Modified: 26 Nov 2024

    Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-31248

    Last Modified: 2 Dec 2024

    Missing Authorization vulnerability in Team Plugins360 All-in-One Video Gallery.This issue affects All-in-One Video Gallery: from n/a through 3.5.2.

    Published: 9 Jun 2024
    9.8
    Critical

    CVE-2024-31244

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

    Published: 9 Jun 2024
    7.5
    High

    CVE-2024-31243

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-30544

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in UPQODE Whizzy.This issue affects Whizzy: from n/a through 1.1.18.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-30529

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.7.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-30517

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-30515

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4.

    Published: 9 Jun 2024
    3.7
    Low

    CVE-2024-30512

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.

    Published: 9 Jun 2024
    8.8
    High

    CVE-2024-30485

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2024-30481

    Last Modified: 14 Mar 2025

    Broken Access Control vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.0.0.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2024-30470

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/a through 1.33.0.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2024-30467

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg.This issue affects Essential Blocks for Gutenberg: from n/a through 4.4.9.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2024-30466

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.4.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2024-30465

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Pagelayer Team PageLayer.This issue affects PageLayer: from n/a through 1.8.1.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2024-30464

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2024-25929

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.5.

    Published: 9 Jun 2024
    8.8
    High

    CVE-2024-25092

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2024-24716

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.6.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2023-34003

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Woo WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.1.51.

    Published: 9 Jun 2024
    8.3
    High

    CVE-2023-31080

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2023-23640

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in MainWP MainWP UpdraftPlus Extension.This issue affects MainWP UpdraftPlus Extension: from n/a through 4.0.6.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2023-23639

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in MainWP MainWP Staging Extension.This issue affects MainWP Staging Extension: from n/a through 4.0.3.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2023-51494

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Woo WooCommerce Product Vendors.This issue affects WooCommerce Product Vendors: from n/a through 2.2.1.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2023-52230

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.3.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2023-52232

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-30539

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2024-30534

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.5.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-30537

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in WPClever WPC Badge Management for WooCommerce.This issue affects WPC Badge Management for WooCommerce: from n/a through 2.4.0.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-30538

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in DELUCKS GmbH DELUCKS SEO.This issue affects DELUCKS SEO: from n/a through 2.5.4.

    Published: 9 Jun 2024
    8.1
    High

    CVE-2024-31098

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Mr.Ebabi New Order Notification for Woocommerce.This issue affects New Order Notification for Woocommerce: from n/a through 2.0.2.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2024-31246

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through <= 3.2.3.

    Published: 9 Jun 2024