shapedplugin records
17 published records for vendor shapedplugin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 35.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-502 Deserialization of Untrusted Data2
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-25065No exploit | WordPress WP Tabs Plugin <= 2.1.14 is vulnerable to Cross Site Request Forgery (CSRF)shapedplugin · wp tabs · CWE-352 | High8.8 | — | 0.3% | Feb 14, 2023 |
32Monitor | CVE-2021-24739No exploit | Logo Carousel < 3.4.2 - Unauthorised Private Post Accessshapedplugin · logo carousel · CWE-639 | High8.1 | — | 1.0% | Dec 21, 2021 |
28Monitor | CVE-2024-3020No exploit | Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 -shapedplugin · carousel, slider, photo gallery with lightbox, video slider, by wp carousel · CWE-502 | High7.2 | — | 1.0% | Apr 10, 2024 |
28Monitor | CVE-2025-48134No exploit | WordPress WP Tabs plugin <= 2.2.12 - PHP Object Injection Vulnerabilityshapedplugin · wp tabs · CWE-502 | High7.2 | — | 0.5% | May 16, 2025 |
24Monitor | CVE-2024-11503No exploit | WP Tabs < 2.2.7 - Admin+ Stored XSSshapedplugin · wp tabs · CWE-79 | Medium6.1 | — | 0.3% | Mar 25, 2025 |
21Monitor | CVE-2021-24738No exploit | Logo Carousel < 3.4.2 - Contributor+ Stored Cross-Site Scriptingshapedplugin · logo carousel · CWE-79 | Medium5.4 | — | 0.6% | Dec 21, 2021 |
21Monitor | CVE-2023-0360No exploit | Location Weather < 1.3.4 - Contributor+ Stored XSSshapedplugin · location weather · CWE-79 | Medium5.4 | — | 0.5% | Feb 13, 2023 |
21Monitor | CVE-2023-0071No exploit | WP Tabs < 2.1.17 - Contributor+ Stored XSSshapedplugin · wp tabs · CWE-79 | Medium5.4 | — | 0.5% | Jan 30, 2023 |
21Monitor | CVE-2023-0537No exploit | Product Slider For WooCommerce Lite <= 1.1.7 - Contributor+ Stored XSSshapedplugin · product slider for woocommerce · CWE-79 | Medium5.4 | — | 0.5% | May 8, 2023 |
21Monitor | CVE-2023-0097No exploit | Post Grid, Post Carousel, & List Category Posts < 2.4.19 - Contributor+ Stored XSSshapedplugin · smart post show · CWE-79 | Medium5.4 | — | 0.5% | Jan 30, 2023 |
21Monitor | CVE-2022-4648No exploit | Real Testimonials < 2.6.0 - Contributor+ Stored XSSshapedplugin · real testimonials · CWE-79 | Medium5.4 | — | 0.5% | Jan 16, 2023 |
21Monitor | CVE-2022-4629No exploit | Product Slider for WooCommerce < 2.6.4 - Contributor+ Stored XSS in Shortcodeshapedplugin · product slider for woocommerce · CWE-79 | Medium5.4 | — | 0.5% | Jan 23, 2023 |
21Monitor | CVE-2024-2949No exploit | Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 -shapedplugin · wp carousel · CWE-79 | Medium5.4 | — | 0.3% | Apr 6, 2024 |
21Monitor | CVE-2023-52124No exploit | WordPress WP Tabs Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS)shapedplugin · wp tabs · CWE-79 | Medium5.4 | — | 0.3% | Jan 5, 2024 |
19Monitor | CVE-2024-8187No exploit | Smart Post Show <= 3.0.0 - Editor+ Stored XSSshapedplugin · smart post show · CWE-79 | Medium4.8 | — | 0.3% | May 15, 2025 |
17Monitor | CVE-2022-2382No exploit | Product Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options Deletionshapedplugin · product slider for woocommerce · CWE-352 | Medium4.3 | — | 0.4% | Aug 22, 2022 |
14Monitor | CVE-2024-3996No exploit | Post Grid, Post Carousel, & List Category Posts < 2.4.28 - Editor+ Stored XSSshapedplugin · smart post show · CWE-79 | Low3.5 | — | 0.3% | May 15, 2025 |
- CVE-2023-2506535Monitor
WordPress WP Tabs Plugin <= 2.1.14 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%shapedplugin · wp tabsFeb 14, 2023
- CVE-2021-2473932Monitor
Logo Carousel < 3.4.2 - Unauthorised Private Post Access
HighCVSS 8.1No exploitEPSS 1%shapedplugin · logo carouselDec 21, 2021
- CVE-2024-302028Monitor
Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 -
HighCVSS 7.2No exploitEPSS 1%shapedplugin · carousel, slider, photo gallery with lightbox, video slider, by wp carouselApr 10, 2024
- CVE-2025-4813428Monitor
WordPress WP Tabs plugin <= 2.2.12 - PHP Object Injection Vulnerability
HighCVSS 7.2No exploitEPSS 0%shapedplugin · wp tabsMay 16, 2025
- CVE-2024-1150324Monitor
WP Tabs < 2.2.7 - Admin+ Stored XSS
MediumCVSS 6.1No exploitEPSS 0%shapedplugin · wp tabsMar 25, 2025
- CVE-2021-2473821Monitor
Logo Carousel < 3.4.2 - Contributor+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%shapedplugin · logo carouselDec 21, 2021
- CVE-2023-036021Monitor
Location Weather < 1.3.4 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%shapedplugin · location weatherFeb 13, 2023
- CVE-2023-007121Monitor
WP Tabs < 2.1.17 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%shapedplugin · wp tabsJan 30, 2023
- CVE-2023-053721Monitor
Product Slider For WooCommerce Lite <= 1.1.7 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%shapedplugin · product slider for woocommerceMay 8, 2023
- CVE-2023-009721Monitor
Post Grid, Post Carousel, & List Category Posts < 2.4.19 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 0%shapedplugin · smart post showJan 30, 2023
- CVE-2022-464821Monitor
Real Testimonials < 2.6.0 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 0%shapedplugin · real testimonialsJan 16, 2023
- CVE-2022-462921Monitor
Product Slider for WooCommerce < 2.6.4 - Contributor+ Stored XSS in Shortcode
MediumCVSS 5.4No exploitEPSS 0%shapedplugin · product slider for woocommerceJan 23, 2023
- CVE-2024-294921Monitor
Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 -
MediumCVSS 5.4No exploitEPSS 0%shapedplugin · wp carouselApr 6, 2024
- CVE-2023-5212421Monitor
WordPress WP Tabs Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%shapedplugin · wp tabsJan 5, 2024
- CVE-2024-818719Monitor
Smart Post Show <= 3.0.0 - Editor+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%shapedplugin · smart post showMay 15, 2025
- CVE-2022-238217Monitor
Product Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options Deletion
MediumCVSS 4.3No exploitEPSS 0%shapedplugin · product slider for woocommerceAug 22, 2022
- CVE-2024-399614Monitor
Post Grid, Post Carousel, & List Category Posts < 2.4.28 - Editor+ Stored XSS
LowCVSS 3.5No exploitEPSS 0%shapedplugin · smart post showMay 15, 2025