Codesupplyco
Codesupplyco Powerkit: vulnerabilities and CVEs
Codesupplyco Powerkit has 6 published vulnerabilities, 5 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months5
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2390 | Medium (6.4) | 0.19% | — | Sep 7, 2026 | The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This is due to the 'content_process_images'… |
| CVE-2026-28178 | Medium (6.5) | 0.22% | — | Aug 6, 2026 | Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. |
| CVE-2026-15649 | Medium (6.4) | 0.35% | — | Aug 1, 2026 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.1.0 due to insufficient input… |
| CVE-2026-15645 | Medium (6.4) | 0.36% | — | Aug 1, 2026 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input… |
| CVE-2026-15644 | Medium (6.4) | 0.36% | — | Aug 1, 2026 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.1.0 due to insufficient input… |
| CVE-2024-2458 | Medium (5.4) | 0.31% | — | Apr 6, 2024 | The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.9.1 due to insufficient input… |