← Back

Mythemeshop

mythemeshop

9 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Url Shortener
url_shortener
Launcher
launcher
Wp Subscribe
wp_subscribe
Wp Shortcode
wp_shortcode

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mythemeshop
1Url Shortener
Jun 17, 2026
Jul 9, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfilte...Show more
The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowedShow less
1Mythemeshop
1Url Shortener
Jun 17, 2026
Jan 17, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17.
1Mythemeshop
1Wp Shortcode
Jun 17, 2026
Nov 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions.
1Mythemeshop
1Url Shortener
Jun 17, 2026
Sep 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions.
1Mythemeshop
1Launcher
Jun 17, 2026
Sep 6, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.
1Mythemeshop
1Wp Subscribe
Jun 17, 2026
May 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.
1Mythemeshop
1My Wp Translate
Nov 21, 2024
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
1Mythemeshop
1My Wp Translate
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
1Mythemeshop
1Launcher
Jun 17, 2026
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3)...Show more
Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3) Meta Description, (4) Subscribe Form (Name field label, Last name field label, Email field label), (5) Contact Form (Name field label and Email field label), and (6) Social Links (Facebook Page URL, Twitter Page URL, Instagram Page URL, YouTube Page URL, Linkedin Page URL, Google+ Page URL, RSS URL).Show less