VYPR
Vendor

Mythemeshop

Products
7
CVEs
9
Across products
10
Status
Private

Products

7

Recent CVEs

9
  • CVE-2017-18569HigAug 20, 2019
    risk 0.57cvss 8.8epss 0.01

    The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.

  • CVE-2023-30472HigSep 27, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions.

  • CVE-2017-18568MedAug 20, 2019
    risk 0.40cvss 6.1epss 0.01

    The my-wp-translate plugin before 1.0.4 for WordPress has XSS.

  • CVE-2023-23896MedJan 17, 2024
    risk 0.35cvss 5.4epss 0.01

    Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17.

  • CVE-2019-7411MedMay 13, 2019
    risk 0.35cvss 5.4epss 0.01

    Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3) Meta Description, (4) Subscribe Form (Name field label,…

  • CVE-2024-5802MedJul 9, 2024
    risk 0.31cvss 4.8epss 0.00

    The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

  • CVE-2021-36829MedSep 6, 2022
    risk 0.31cvss 4.8epss 0.00

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.

  • CVE-2023-28495MedNov 12, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions.

  • CVE-2021-36844LowMay 2, 2022
    risk 0.22cvss 3.4epss 0.01

    Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.