Vulnerabilities
Summary — last 7 days
New vulnerabilities2,674▼ 561 vs. last week
Critical / high1,270▼ 252 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)217▼ 222 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.5) | 0.53% | — | Wordpress Simple Shopping CartAI | 4/23/2025 | 6/17/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'product_tmp_two' for computing a… | |
| Deferred | High (8.2) | 0.40% | — | Wordpress Simple Shopping CartAI | 4/23/2025 | 6/17/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and download a digital product without paying… | |
| Modified | Medium (6.1) | 0.90% | — | Wordpress Simple Shop Project Wordpress Simple Shop | 9/10/2021 | 6/17/2026 | The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2. |