Where
-Infinity
0

WordPress Simple Shopping CartWordPress Simple PayPal Shopping Cart <= 5.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Risk 28
Severity
6.4
EPSS
0.03%
First published (updated )

WordPress Simple Shopping CartWordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference

Risk 28
Severity
6.5
EPSS
0.10%
First published (updated )

WordPress Simple Shopping CartWordPress Simple PayPal Shopping Cart <= 5.1.3 - Insecure Direct Object Reference via 'quantity'

Risk 19
Severity
5.3
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wp Estore WordpressWP eStore < 8.5.6 - Reflected XSS in Product Editing

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wp Estore WordpressWP eStore < 8.5.6 - Reflected XSS in Customer Search

Risk 34
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Tipsandtricks-hq Wp Estore WordpressWP eStore < 8.5.6 - Settings Reset via CSRF

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

WP eMemberWP eMember <= v10.7.0 - Stored XSS via CSRF

Risk 38
Severity
6.1
First published (updated )

Sye WP Affiliate PlatformWP Affiliate Platform < 6.5.2 - Affiliate Deletion via CSRF

Risk 33
Severity
5.5
First published (updated )

Tipsandtricks-hq Wp Estore WordpressWP eStore < 8.5.5 - Reflected XSS in Customer Editing

Risk 27
Severity
6.1
EPSS
0.05%
First published (updated )

Tipsandtricks-hq Wp Estore WordpressWP eStore < 8.5.5 - Reflected XSS in Category Editing

Risk 27
Severity
6.1
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Tipsandtricks-hq Wp Estore WordpressWP eStore < 8.5.5 - Coupon Deletion via CSRF

Risk 56
Severity
8.8
EPSS
0.06%
First published (updated )

Tipsandtricks-hq Wp Estore WordpressWP eStore < 8.5.5 - Reflected XSS via $_SERVER['REQUEST_URI']

Risk 27
Severity
6.1
EPSS
0.05%
First published (updated )

Tipsandtricks-hq Wp Estore WordpressWP eStore < 8.5.5 - Reflected XSS in Discount Editing

Risk 27
Severity
6.1
EPSS
0.05%
First published (updated )

WP eMember WP eMemberWP eMember < 10.6.7 - Reflected XSS

Risk 38
Severity
6.8
EPSS
0.04%
First published (updated )

WordPress wp-eMemberWP eMember < 10.6.7 - Reflected XSS via Member Edit

Risk 36
Severity
7.1
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Tipsandtricks-hq Wp Affiliate Platform WordpressWP Affiliate Platform < 6.5.1 - Reflected XSS via Banner Editing

Risk 22
Severity
4.8
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wp Affiliate Platform WordpressWP Affiliate Platform < 6.5.1 - Profile Update via CSRF

Risk 36
Severity
7.1
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wp Affiliate Platform WordpressWP Affiliate Platform < 6.5.1 - Reflected XSS via Lead Editing

Risk 27
Severity
6.1
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wp Affiliate Platform WordpressWP Affiliate Platform < 6.5.1 - Reflected XSS via Registration Form

Risk 27
Severity
6.1
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wp Affiliate Platform WordpressWP Affiliate Platform < 6.5.1 - Stored XSS via CSRF

Risk 38
Severity
6.8
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Tipsandtricks-hq Wp Affiliate Platform WordpressWP Affiliate Platform < 6.5.1 - POST Reflected XSS

Risk 17
Severity
4.7
EPSS
0.04%
First published (updated )

WP Affiliate Platform WP Affiliate PlatformWP Affiliate Platform < 6.5.1 - Reflected XSS via Affiliate Editing

Risk 27
Severity
6.1
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wp Emember WordpressWP eMember < 10.6.7 - Unauthenticated Stored XSS via Member Registration

Risk 27
Severity
6.1
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wp Emember WordpressWP eMember < 10.6.6 - Stored XSS in Blacklist via CSRF

Risk 38
Severity
6.8
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wp Emember WordpressWP eMember < 10.6.6 - Admin+ Arbitrary File Upload

Risk 56
Severity
8.8
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

wp-eMember WordPress pluginWP eMember < 10.6.6 - Bulk Delete via CSRF

Risk 56
Severity
8.8
EPSS
0.04%
First published (updated )

WP eMember WP eMemberWP eMember < 10.6.6 - Reflected XSS

Risk 30
Severity
5.9
EPSS
0.04%
First published (updated )

WP eMember WP eMemberWP eMember < 10.6.6 - Reflected XSS

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

WP eMember WP eMemberWP eMember < 10.3.9 - Reflected XSS

Risk 40
Severity
8.3
EPSS
0.04%
First published (updated )

Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart WordpressWordPress Simple Shopping Cart <= 4.7.1 - Authenticated(Administrator+) Stored Cross-Site Scripting

Risk 29
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203