CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2023-46205

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.14.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2023-46197

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-46145

    Last Modified: 28 Apr 2026

    Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5.

    Published: 17 May 2024
    6.5
    Medium

    CVE-2023-45652

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Justin Silver Remote Content Shortcode allows PHP Local File Inclusion.This issue affects Remote Content Shortcode: from n/a through 1.5.

    Published: 17 May 2024
    6.4
    Medium

    CVE-2024-4789

    Last Modified: 15 Apr 2026

    Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.72, via the send_demo_webhook() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 17 May 2024
    7.1
    High

    CVE-2023-44478

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-24873

    Last Modified: 15 Apr 2026

    : Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-24874

    Last Modified: 15 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-25595

    Last Modified: 28 May 2025

    Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.

    Published: 17 May 2024
    4.3
    Medium

    CVE-2024-25906

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in WP Happy Coders Comments Like Dislike allows Functionality Bypass.This issue affects Comments Like Dislike: from n/a through 1.2.2.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-30479

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue affects IP Blocker Lite: from n/a through 11.1.1.

    Published: 17 May 2024
    3.7
    Low

    CVE-2024-30480

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-30522

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.

    Published: 17 May 2024
    7.5
    High

    CVE-2024-30527

    Last Modified: 15 Apr 2026

    Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-30540

    Last Modified: 15 Apr 2026

    Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form: from n/a through 14.7.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-31295

    Last Modified: 28 Apr 2026

    Guessable CAPTCHA vulnerability in BestWebSoft Captcha by BestWebSoft allows Functionality Bypass.This issue affects Captcha by BestWebSoft: from n/a through 5.2.0.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-31341

    Last Modified: 28 Apr 2026

    Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-32131

    Last Modified: 21 Mar 2025

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.

    Published: 17 May 2024
    4.3
    Medium

    CVE-2024-32790

    Last Modified: 15 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.

    Published: 17 May 2024
    8.8
    High

    CVE-2024-33549

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10.

    Published: 17 May 2024
    8.8
    High

    CVE-2024-33550

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in JR King/Eran Schoellhorn WP Masquerade allows Privilege Escalation.This issue affects WP Masquerade: from n/a through 1.1.0.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2024-33552

    Last Modified: 10 Apr 2025

    Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2024-33567

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.

    Published: 17 May 2024
    7.2
    High

    CVE-2024-33569

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Darren Cooney Instant Images allows Privilege Escalation.This issue affects Instant Images: from n/a through 6.1.0.

    Published: 17 May 2024
    9.9
    Critical

    CVE-2024-33644

    Last Modified: 15 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affects Customify Site Library: from n/a through 0.0.9.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-33917

    Last Modified: 28 Apr 2026

    Authentication Bypass by Spoofing vulnerability in webtechideas WTI Like Post allows Functionality Bypass.This issue affects WTI Like Post: from n/a through 1.4.6.

    Published: 17 May 2024
    7.2
    High

    CVE-2024-34370

    Last Modified: 28 Apr 2026

    Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.

    Published: 17 May 2024
    6.5
    Medium

    CVE-2024-34434

    Last Modified: 10 Apr 2025

    Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.2.

    Published: 17 May 2024
    5.5
    Medium

    CVE-2024-35110

    Last Modified: 10 Jun 2025

    A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.

    Published: 17 May 2024
    8.6
    High

    CVE-2023-41957

    Last Modified: 25 Mar 2025

    Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-41956

    Last Modified: 25 Mar 2025

    Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-41955

    Last Modified: 12 Jul 2025

    Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.

    Published: 17 May 2024
    8.6
    High

    CVE-2023-41954

    Last Modified: 9 Jun 2025

    Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-41665

    Last Modified: 28 Apr 2026

    Improper Privilege Management vulnerability in GiveWP allows Privilege Escalation.This issue affects GiveWP: from n/a through 2.33.0.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-41243

    Last Modified: 10 Apr 2025

    Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90.

    Published: 17 May 2024
    8.6
    High

    CVE-2023-39163

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Shop allows PHP Local File Inclusion.This issue affects Phlox Shop: from n/a through 2.0.0.

    Published: 17 May 2024
    8.6
    High

    CVE-2023-38399

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Portfolio allows PHP Local File Inclusion.This issue affects Phlox Portfolio: from n/a through 2.3.1.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2023-37999

    Last Modified: 29 Jan 2025

    Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

    Published: 17 May 2024
    7.6
    High

    CVE-2023-37888

    Last Modified: 29 May 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in By Averta Shortcodes and extra features for Phlox theme allows PHP Local File Inclusion.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.14.0.

    Published: 17 May 2024
    7.2
    High

    CVE-2023-37866

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.

    Published: 17 May 2024
    8.8
    High

    CVE-2023-37389

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.

    Published: 17 May 2024
    7.3
    High

    CVE-2023-37385

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through 6.5.6.

    Published: 17 May 2024
    7.6
    High

    CVE-2023-35881

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2023-34186

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Imran Sayed Headless CMS.This issue affects Headless CMS: from n/a through 2.0.3.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2023-33321

    Last Modified: 3 Feb 2025

    Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.

    Published: 17 May 2024
    6
    Medium

    CVE-2023-33310

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Valiano Unite Gallery Lite allows PHP Local File Inclusion.This issue affects Unite Gallery Lite: from n/a through 1.7.59.

    Published: 17 May 2024
    9
    Critical

    CVE-2023-32297

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: from n/a through 2.2.6.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2023-32244

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in xtemos Woodmart Core allows Privilege Escalation.This issue affects Woodmart Core: from n/a through 1.0.36.

    Published: 17 May 2024
    4.3
    Medium

    CVE-2023-32129

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9.

    Published: 17 May 2024
    7.6
    High

    CVE-2023-32110

    Last Modified: 19 Mar 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in artbees JupiterX allows PHP Local File Inclusion.This issue affects JupiterX: from n/a through 3.0.0.

    Published: 17 May 2024