Vulnerabilities

Summary — last 7 days

New vulnerabilities2,674▼ 561 vs. last week
Critical / high1,270▼ 252 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)217▼ 222 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.5)0.53%—Wordpress Simple Shopping CartAI4/23/20256/17/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'product_tmp_two' for computing a…
DeferredHigh (8.2)0.40%—Wordpress Simple Shopping CartAI4/23/20256/17/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and download a digital product without paying…
ModifiedMedium (6.1)0.90%—Wordpress Simple Shop Project Wordpress Simple Shop9/10/20216/17/2026
The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.