VYPR

Flexi Product Slider and Grid for WooCommerce

by WordPress

CVEs (1)

  • CVE-2026-1988HigFeb 14, 2026
    risk 0.49cvss 7.5epss 0.01

    The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel` shortcode. This is due to the `theme` parameter being directly concatenated into a file path…