Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Tabs HIGH 7.2
CVE-2025-48134

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs wp-expand-tabs-free allows Object Injection.This issue affects WP Tabs: f…

Fix: after 2.2.11
Fix from $1,950 2025-05-16
Wp Tabs MEDIUM 6.1
CVE-2024-11503

The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to…

Fix: 2.2.7+
Fix from $1,600 2025-03-25
Wp Carousel MEDIUM 5.4
CVE-2024-2949

The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooComm…

Fix: 2.6.4+
Fix from $1,600 2024-04-06
Wp Tabs MEDIUM 5.4
CVE-2023-52124

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC WP Tabs – Responsive Tabs Plug…

Fix: after 2.2.0
Fix from $1,600 2024-01-05
Product Slider For Woocommerce MEDIUM 5.4
CVE-2023-0537

The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputtin…

Fix: after 1.1.7
Fix from $1,600 2023-05-08
Wp Tabs HIGH 8.8
CVE-2023-25065

Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14 versions.

Fix: 2.1.15+
Fix from $1,950 2023-02-14
Location Weather MEDIUM 5.4
CVE-2023-0360

The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputting them back in a page/post …

Fix: 1.3.4+
Fix from $1,600 2023-02-13
Wp Tabs MEDIUM 5.4
CVE-2023-0071

The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post w…

Fix: 2.1.17+
Fix from $1,600 2023-01-30
Smart Post Show MEDIUM 5.4
CVE-2023-0097

The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outp…

Fix: 2.4.19+
Fix from $1,600 2023-01-30
Product Slider For Woocommerce MEDIUM 5.4
CVE-2022-4629

The Product Slider for WooCommerce WordPress plugin before 2.6.4 does not validate and escape some of its shortcode attributes before outputting them…

Fix: 2.6.4+
Fix from $1,600 2023-01-23
Real Testimonials MEDIUM 5.4
CVE-2022-4648

The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the …

Fix: 2.6.0+
Fix from $1,600 2023-01-16
Logo Carousel HIGH 8.1
CVE-2021-24739

The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by …

Fix: 3.4.2+
Fix from $1,950 2021-12-21
Logo Carousel MEDIUM 5.4
CVE-2021-24738

The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role a…

Fix: 3.4.2+
Fix from $1,600 2021-12-21