漏洞列表 352348
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2026-24605
WordPress X Addons for Elementor plugin <= 1.0.23 - Broken Access Control vulnerability
MEDIUM 4.3 2026-01-23
pencilwp X Addons for Elementor
CVE NVD
CVE-2026-24604
WordPress Simple GDPR Cookie Compliance plugin <= 2.0.0 - Broken Access Control vulnerability
MEDIUM 5.3 2026-01-23
themebeez Simple GDPR Cookie Compliance
CVE NVD
CVE-2026-24603
WordPress Universal Google Adsense and Ads manager plugin <= 1.1.8 - Broken Access Control vulnerability
MEDIUM 5.3 2026-01-23
themebeez Universal Google Adsense and Ads manager
CVE NVD
CVE-2026-24602
WordPress Raptive Ads plugin <= 3.10.0 - Broken Access Control vulnerability
MEDIUM 5.3 2026-01-23
Raptive Raptive Ads
CVE NVD
CVE-2026-24601
WordPress Penci Pay Writer plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability
MEDIUM 5.4 2026-01-23
PenciDesign Penci Pay Writer
CVE NVD
CVE-2026-24600
WordPress Penci Review plugin <= 3.5 - Cross Site Scripting (XSS) vulnerability
MEDIUM 5.4 2026-01-23
PenciDesign Penci Review
CVE NVD
CVE-2026-24599
WordPress NextMove Lite plugin <= 2.23.0 - Insecure Direct Object References (IDOR) vulnerability
MEDIUM 5.3 2026-01-23
XLPlugins NextMove Lite
CVE NVD
CVE-2026-24598
WordPress Multilanguage by BestWebSoft plugin <= 1.5.2 - Broken Access Control vulnerability
MEDIUM 4.3 2026-01-23
bestwebsoft Multilanguage by BestWebSoft
CVE NVD
CVE-2026-24596
WordPress Related Posts Thumbnails Plugin for WordPress plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerability
MEDIUM 4.7 2026-01-23
marynixie Related Posts Thumbnails Plugin for WordPress
CVE NVD
CVE-2026-24595
WordPress Zoho CRM Lead Magnet plugin <= 1.8.1.5 - Broken Access Control vulnerability
MEDIUM 5.4 2026-01-23
zohocrm Zoho CRM Lead Magnet
CVE NVD
CVE-2026-24594
WordPress Livemesh Addons for WPBakery Page Builder plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability
MEDIUM 4.8 2026-01-23
livemesh Livemesh Addons for WPBakery Page Builder
CVE NVD
CVE-2026-24593
WordPress AWP Classifieds plugin <= 4.4.3 - Sensitive Data Exposure vulnerability
MEDIUM 5.3 2026-01-23
Strategy11 Team AWP Classifieds
CVE NVD
CVE-2026-24591
WordPress Turn Yoast SEO FAQ Block to Accordion plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability
MEDIUM 5.4 2026-01-23
yasir129 Turn Yoast SEO FAQ Block to Accordion
CVE NVD
CVE-2026-24589
WordPress Cargus plugin <= 1.5.8 - Sensitive Data Exposure vulnerability
MEDIUM 5.3 2026-01-23
Cargus eCommerce Cargus
CVE NVD
CVE-2026-24588
WordPress Smart Product Viewer plugin <= 1.5.4 - Broken Access Control vulnerability
MEDIUM 4.3 2026-01-23
topdevs Smart Product Viewer
CVE NVD
CVE-2026-24587
WordPress AJAX Hits Counter + Popular Posts Widget plugin <= 0.10.210305 - Broken Access Control vulnerability
MEDIUM 5.4 2026-01-23
kutsy AJAX Hits Counter + Popular Posts Widget
CVE NVD
CVE-2026-24585
WordPress Hyyan WooCommerce Polylang Integration plugin <= 1.5.0 - Broken Access Control vulnerability
MEDIUM 6.5 2026-01-23
Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration
CVE NVD
CVE-2026-24584
WordPress Tutor LMS BunnyNet Integration plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability
MEDIUM -1.0 2026-01-23
Themeum Tutor LMS BunnyNet Integration
CVE NVD
CVE-2026-24583
WordPress SumUp Payment Gateway For WooCommerce plugin <= 2.7.9 - Broken Access Control vulnerability
MEDIUM 5.3 2026-01-23
sumup SumUp Payment Gateway For WooCommerce
CVE NVD
CVE-2026-24581
WordPress Points and Rewards for WooCommerce plugin <= 2.9.5 - Broken Access Control vulnerability
MEDIUM 5.4 2026-01-23
WP Swings Points and Rewards for WooCommerce
CVE NVD