Codesupplyco
Codesupplyco Powerkit: vulnerabilidades y CVE
Codesupplyco Powerkit tiene 6 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2390 | Media (6.4) | 0.19% | — | 7 sept 2026 | The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This is due to the 'content_process_images'… |
| CVE-2026-28178 | Media (6.5) | 0.22% | — | 6 ago 2026 | Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. |
| CVE-2026-15649 | Media (6.4) | 0.35% | — | 1 ago 2026 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.1.0 due to insufficient input… |
| CVE-2026-15645 | Media (6.4) | 0.36% | — | 1 ago 2026 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input… |
| CVE-2026-15644 | Media (6.4) | 0.36% | — | 1 ago 2026 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input… |
| CVE-2024-2458 | Media (5.4) | 0.31% | — | 6 abr 2024 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.9.1 due to insufficient input… |