CVE Browser

Page 1 (more results available)

Vendor: Shapedplugin Remove filter Clear all
CVE-2026-18988 MEDIUM

Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute

CVSS 6.4 EPSS 0.35% Aug 8, 2026
CVE-2026-66433 MEDIUM

WordPress Location Weather plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.22% Jul 27, 2026
CVE-2026-15652 MEDIUM

Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute

CVSS 6.4 EPSS 0.33% Jul 16, 2026
CVE-2026-59521 HIGH

WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerability

CVSS 7.2 EPSS 0.54% Jul 13, 2026
CVE-2026-49777 CRITICAL

WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability

CVSS 10.0 EPSS 2.02% Jun 5, 2026
CVE-2026-7249 MEDIUM

Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contributor+) Block Settings Modification and Cache Purging

CVSS 4.3 EPSS 0.35% May 22, 2026
CVE-2026-4665 MEDIUM

WP Carousel Free <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-caption' Attribute

CVSS 6.4 EPSS 0.33% May 5, 2026
CVE-2026-3017 HIGH

Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection

CVSS 7.2 EPSS 0.69% Apr 14, 2026
CVE-2025-12584 MEDIUM

Quick View for WooCommerce <= 2.2.17 - Unauthenticated Private Product Disclosure

CVSS 5.3 EPSS 0.26% Nov 27, 2025
CVE-2025-58228 MEDIUM

WordPress Quick View for WooCommerce Plugin <= 2.2.16 - Cross Site Scripting (XSS) Vulnerability

CVSS 6.5 EPSS 0.22% Sep 22, 2025
CVE-2025-48134 HIGH

WordPress WP Tabs plugin <= 2.2.12 - PHP Object Injection Vulnerability

CVSS 7.2 EPSS 0.46% May 16, 2025
CVE-2024-3996 LOW

Post Grid, Post Carousel, & List Category Posts < 2.4.28 - Editor+ Stored XSS

CVSS 3.5 EPSS 0.32% May 15, 2025
CVE-2024-8187 MEDIUM

Smart Post Show <= 3.0.0 - Editor+ Stored XSS

CVSS 4.8 EPSS 0.30% May 15, 2025
CVE-2025-22269 MEDIUM

WordPress Real Testimonials plugin <= 3.1.6 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.27% Apr 15, 2025
CVE-2024-11503 MEDIUM

WP Tabs < 2.2.7 - Admin+ Stored XSS

CVSS 6.1 EPSS 0.27% Mar 25, 2025
CVE-2023-41132 MEDIUM

WordPress Category Slider for WooCommerce plugin <= 1.4.15 - Broken Access Control vulnerability

CVSS 4.3 EPSS 0.47% Dec 13, 2024
CVE-2024-5020 MEDIUM

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

CVSS 6.4 EPSS 0.43% Dec 4, 2024
CVE-2024-32801 MEDIUM

WordPress Widget Post Slider plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability

CVSS 5.9 EPSS 0.34% Apr 24, 2024
CVE-2024-3020 HIGH

Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3…

CVSS 7.2 EPSS 0.97% Apr 10, 2024
CVE-2024-2949 MEDIUM

Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3…

CVSS 6.4 EPSS 0.34% Apr 6, 2024
CVE-2024-1363 MEDIUM

Easy Accordion – Best Accordion FAQ Plugin for WordPress <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVSS 6.4 EPSS 0.40% Mar 13, 2024
CVE-2023-52124 MEDIUM

WordPress WP Tabs Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS)

CVSS 6.5 EPSS 0.30% Jan 5, 2024
CVE-2023-0537 MEDIUM

Product Slider For WooCommerce Lite <= 1.1.7 - Contributor+ Stored XSS

CVSS 5.4 EPSS 0.50% May 8, 2023
CVE-2023-25065 HIGH

WordPress WP Tabs Plugin <= 2.1.14 is vulnerable to Cross Site Request Forgery (CSRF)

CVSS 8.8 EPSS 0.26% Feb 14, 2023
CVE-2023-0360 MEDIUM

Location Weather < 1.3.4 - Contributor+ Stored XSS

CVSS 5.4 EPSS 0.54% Feb 13, 2023

Showing 1 to 25 CVEs · page 1 (more available)