CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2024-5054

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 17 May 2024
    8.2
    High

    CVE-2024-32692

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 6.9.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-32685

    Last Modified: 7 Feb 2025

    Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

    Published: 17 May 2024
    8.8
    High

    CVE-2024-32680

    Last Modified: 20 Mar 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY – Products Filter for WooCommerce (formerly WOOF) allows Using Malicious Files, Code Inclusion.This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.5.2.

    Published: 17 May 2024
    8.1
    High

    CVE-2024-32523

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in EverPress Mailster mailster.This issue affects Mailster: from n/a through <= 4.0.6.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-32521

    Last Modified: 28 Apr 2026

    Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-32512

    Last Modified: 15 Apr 2026

    Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2024-32511

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalation.This issue affects Simple Registration for WooCommerce: from n/a through 1.5.6.

    Published: 17 May 2024
    8.8
    High

    CVE-2024-32507

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.16.

    Published: 17 May 2024
    8.5
    High

    CVE-2024-31300

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2024-31290

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.

    Published: 17 May 2024
    6.3
    Medium

    CVE-2024-31281

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.6.

    Published: 17 May 2024
    7.5
    High

    CVE-2024-31237

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.

    Published: 17 May 2024
    8
    High

    CVE-2024-31232

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.

    Published: 17 May 2024
    9
    Critical

    CVE-2024-31231

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2024-30542

    Last Modified: 21 Mar 2025

    Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects WholesaleX: from n/a through 1.3.2.

    Published: 17 May 2024
    6.5
    Medium

    CVE-2024-30509

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Artbees SellKit allows Relative Path Traversal.This issue affects SellKit: from n/a through 1.8.1.

    Published: 17 May 2024
    8.3
    High

    CVE-2024-27971

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce woo-permalink-manager.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through <= 2.3.10.

    Published: 17 May 2024
    8.8
    High

    CVE-2024-27955

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Automatic Automatic allows Privilege Escalation.This issue affects Automatic: from n/a through 3.92.0.

    Published: 17 May 2024
    9.3
    Critical

    CVE-2024-27954

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.

    Published: 17 May 2024
    8.5
    High

    CVE-2024-24934

    Last Modified: 29 Jan 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2024-24882

    Last Modified: 1 Apr 2026

    Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2.

    Published: 17 May 2024
    7.5
    High

    CVE-2024-24869

    Last Modified: 9 Jun 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.

    Published: 17 May 2024
    6.5
    Medium

    CVE-2024-24715

    Last Modified: 15 Apr 2026

    Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-23522

    Last Modified: 28 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2024-22157

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects SalesKing: from n/a through 1.6.15.

    Published: 17 May 2024
    8.8
    High

    CVE-2024-22145

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.

    Published: 17 May 2024
    3.7
    Low

    CVE-2024-22139

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This issue affects WordPress Manutenção: from n/a through 1.0.6.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-21746

    Last Modified: 29 Apr 2026

    Authentication Bypass by Spoofing vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Identity Spoofing.This issue affects Wp Ultimate Review: from n/a through <= 2.3.6.

    Published: 17 May 2024
    2.7
    Low

    CVE-2024-4214

    Last Modified: 28 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.

    Published: 17 May 2024
    7.2
    High

    CVE-2023-51546

    Last Modified: 11 Feb 2025

    Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2023-51483

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2023-51481

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in powerfulwp Local Delivery Drivers for WooCommerce allows Privilege Escalation.This issue affects Local Delivery Drivers for WooCommerce: from n/a through 1.9.0.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-51479

    Last Modified: 5 Feb 2025

    Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2023-51476

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in IOSS WP MLM Unilevel allows Privilege Escalation.This issue affects WP MLM Unilevel: from n/a through 4.0.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2023-51424

    Last Modified: 28 Apr 2026

    Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.

    Published: 17 May 2024
    6.3
    Medium

    CVE-2023-51401

    Last Modified: 13 May 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Relative Path Traversal.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.13.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-51398

    Last Modified: 13 May 2025

    Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-51356

    Last Modified: 29 May 2025

    Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-50890

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.20.

    Published: 17 May 2024
    7.5
    High

    CVE-2023-49753

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spoonthemes Adifier System allows PHP Local File Inclusion.This issue affects Adifier System: from n/a before 3.1.4.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-48757

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.

    Published: 17 May 2024
    6.8
    Medium

    CVE-2023-48319

    Last Modified: 15 Apr 2025

    Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.

    Published: 17 May 2024
    7.3
    High

    CVE-2023-47868

    Last Modified: 28 Apr 2026

    Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.3.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-47782

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Thrive Themes Thrive Theme Builder allows Privilege Escalation.This issue affects Thrive Theme Builder: from n/a before 3.24.0.

    Published: 17 May 2024
    8
    High

    CVE-2023-47683

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Privilege Escalation.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.6.

    Published: 17 May 2024
    7.2
    High

    CVE-2023-47682

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.

    Published: 17 May 2024
    6.4
    Medium

    CVE-2023-47679

    Last Modified: 5 Feb 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QODE Interactive Qi Addons For Elementor allows PHP Local File Inclusion.This issue affects Qi Addons For Elementor: from n/a through 1.6.3.

    Published: 17 May 2024
    8.6
    High

    CVE-2023-47178

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows PHP Local File Inclusion.This issue affects The Plus Addons for Elementor Pro: from n/a through 5.2.8.

    Published: 17 May 2024
    8.2
    High

    CVE-2023-46784

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Absolute Path Traversal, : Server Side Request Forgery.This issue affects ICS Calendar: from n/a through 10.12.0.3.

    Published: 17 May 2024