plugin

Post Type X Vulnerabilities

8 known security issues reported for the Post Type X WordPress plugin. Most recent disclosed Oct 16, 2025.

8 medium

Running Post Type X on your site? Check whether your installed version is affected.

Scan your site free

Product Catalog Simple <= 1.8.4 - Cross-Site Request Forgery

medium

The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a sit...

CVSS:
4.3
Affected:
up to 1.8.4
Fixed in:
1.8.5
Disclosed:
Oct 16, 2025

CVE-2025-62061 on NVD →

Product Catalog Simple <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 1.8.2
Fixed in:
1.8.3
Disclosed:
Sep 22, 2025

CVE-2025-58992 on NVD →

Product Catalog Simple <= 1.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 1.8.1
Fixed in:
1.8.2
Disclosed:
Jun 5, 2025

CVE-2025-49305 on NVD →

Product Catalog Simple <= 1.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via show_products Shortcode

medium

The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_products shortcode in all versions up to, and including, 1.7.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...

CVSS:
6.4
Affected:
up to 1.7.11
Fixed in:
1.8.0
Disclosed:
Feb 27, 2025

CVE-2025-1405 on NVD →

Product Catalog Simple <= 1.7.6 - Sensitive Information Exposure via Product CSV

medium

The Product Catalog Simple plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 1.7.7 (exclusive) via Import and Export Product CSV files. This makes it possible for unauthenticated attackers access and above, to extract sensitive data including full product information.

CVSS:
5.3
Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Dec 27, 2023

CVE-2023-51687 on NVD →

Product Catalog Simple <= 1.7.5 - Cross-Site Request Forgery via ic_system_status

medium

The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.5. This is due to missing or incorrect nonce validation on the ic_system_status function. This makes it possible for unauthenticated attackers to reset product settings, delete products,...

CVSS:
4.3
Affected:
up to 1.7.5
Fixed in:
1.7.6
Disclosed:
Nov 8, 2023

Product Catalog Simple <= 1.6.17 - Reflected Cross-Site Scripting

medium

The Product Catalog Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 1.7.0
Fixed in:
1.7.0
Disclosed:
Apr 6, 2023

CVE-2023-29388 on NVD →

Product Catalog Simple <= 1.5.13 - Cross-Site Request Forgery Bypass

medium

The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.13. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to update product meta via a for...

CVSS:
4.3
Affected:
up to 1.5.13
Fixed in:
1.5.13
Disclosed:
Sep 16, 2020

CVE-2020-36743 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database