Filter
-Infinity
0

Hasthemes HashbarWordPress HashBar – WordPress Notification Bar Plugin <= 1.4.1 is vulnerable to Cross Site Scripting (XSS)

First published (updated )

Hasthemes HashbarHashBar – WordPress Notification Bar < 1.3.6 - Contributor+ Stored XSS via Shortcode

First published (updated )

Absolute Addons For ElementorHT Mega – Absolute Addons For Elementor <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

7.2
First published (updated )

Absolute Addons For ElementorHT Mega – Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

First published (updated )

Absolute Addons For ElementorHT Mega – Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

ShopLentorShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module

First published (updated )

ShopLentorThe ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (fo…

EPSS
0.04%
First published (updated )

HasThemes WP TemplataWordPress WP Templata plugin <= 1.0.7 - Reflected Cross Site Scripting (XSS) vulnerability

7.1
EPSS
0.03%
First published (updated )

HasThemes ShopLentorShopLentor < 2.5.4 - PHP Object Injection

First published (updated )

HasThemes ShopLentorShopLentor < 2.5.4 - Contributor+ Stored XSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Hasthemes Ht Easy Ga4 (Google Analytics 4)The HT Easy GA4 – Google Analytics WordPress Plugin plugin for WordPress is vulnerable to unauthoriz…

First published (updated )

Ht PortfolioHT Portfolio < 1.1.6 - Arbitrary Plugin Activation via CSRF

First published (updated )

Hasthemes QuickswishQuickSwish < 1.1.0 - Arbitrary Plugin Activation via CSRF

First published (updated )

Hasthemes Ever CompareEver Compare <= 1.2.3 - Arbitrary Plugin Activation via CSRF

First published (updated )

WP Plugin ManagerWP Plugin Manager < 1.1.8 - Arbitrary Plugin Activation via CSRF

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Hasthemes Ht Slider For ElementorHT Slider For Elementor < 1.4.0 - Arbitrary Plugin Activation via CSRF

First published (updated )

Hasthemes WP EducationWP Education < 1.2.7 - Arbitrary Plugin Activation via CSRF

First published (updated )

HasThemes Free WooCommerce Theme 99fy ExtensionFree WooCommerce Theme 99fy Extension < 1.2.8 - Arbitrary Plugin Activation via CSRF

First published (updated )

Hasthemes Preview Link GeneratorPreview Link Generator < 1.0.4 - Arbitrary Plugin Activation via CSRF

First published (updated )

Hasthemes WP NewsWP News <= 1.1.9 - Arbitrary Plugin Activation via CSRF

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Hasthemes WP InsuranceWP Insurance < 2.1.4 - Arbitrary Plugin Activation via CSRF

First published (updated )

Hasthemes Contact Form 7 Widget For Elementor Page Builder & Gutenberg BlocksContact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks < 1.1.6 - Arbitrary Plugin Activation via CSRF

First published (updated )

Hasthemes WP Film StudioWP Film Studio < 1.3.5 - Arbitrary Plugin Activation via CSRF

First published (updated )

Hasthemes Coupon ZenCoupon Zen < 1.0.6 - Arbitrary Plugin Activation via CSRF

First published (updated )

HasThemes HT PoliticHT Politic < 2.3.8 - Arbitrary Plugin Activation via CSRF

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Hasthemes WC Sales NotificationWC Sales Notification < 1.2.3 - Arbitrary Plugin Activation via CSRF

First published (updated )

Hasthemes Ht EventHT Event < 1.4.6 - Arbitrary Plugin Activation via CSRF

First published (updated )

HasThemes CF7 ExtensionsWordPress Extensions For CF7 Plugin <= 3.2.0 - Server Side Request Forgery (SSRF) vulnerability

EPSS
0.04%
First published (updated )

HasThemes HT Mega WordPressWordPress HT Mega plugin <= 2.5.7 - JSON Path Traversal vulnerability

8.8
First published (updated )

Absolute Addons For ElementorHT Mega <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203