Mythemeshop
Products
7- 3 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18569 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The my-wp-translate plugin before 1.0.4 for WordPress has CSRF. | ||
| CVE-2023-30472 | Hig | 0.46 | 7.1 | 0.00 | Sep 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions. | ||
| CVE-2017-18568 | Med | 0.40 | 6.1 | 0.01 | Aug 20, 2019 | The my-wp-translate plugin before 1.0.4 for WordPress has XSS. | ||
| CVE-2023-23896 | Med | 0.35 | 5.4 | 0.01 | Jan 17, 2024 | Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17. | ||
| CVE-2019-7411 | Med | 0.35 | 5.4 | 0.01 | May 13, 2019 | Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3) Meta Description, (4) Subscribe Form (Name field label,… | ||
| CVE-2024-5802 | Med | 0.31 | 4.8 | 0.00 | Jul 9, 2024 | The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | ||
| CVE-2021-36829 | Med | 0.31 | 4.8 | 0.00 | Sep 6, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress. | ||
| CVE-2023-28495 | Med | 0.28 | 4.3 | 0.00 | Nov 12, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions. | ||
| CVE-2021-36844 | Low | 0.22 | 3.4 | 0.01 | May 2, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress. |
- risk 0.57cvss 8.8epss 0.01
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions.
- risk 0.40cvss 6.1epss 0.01
The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
- risk 0.35cvss 5.4epss 0.01
Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17.
- risk 0.35cvss 5.4epss 0.01
Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3) Meta Description, (4) Subscribe Form (Name field label,…
- risk 0.31cvss 4.8epss 0.00
The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- risk 0.31cvss 4.8epss 0.00
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions.
- risk 0.22cvss 3.4epss 0.01
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.