plugin

Thecartpress Vulnerabilities

6 known security issues reported for the Thecartpress WordPress plugin. Most recent disclosed May 10, 2026.

1 critical 2 high 3 medium

Running Thecartpress on your site? Check whether your installed version is affected.

Scan your site free

TheCartPress eCommerce Shopping Cart <= 1.5.3.6 - Unauthenticated Privilege Escalation

critical

The TheCartPress eCommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.5.3.6. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CVSS:
9.8
Affected:
up to 1.5.3.6
Fix:
No patched version reported
Disclosed:
May 10, 2026

CVE-2021-47932 on NVD →

TheCartPress eCommerce Shopping Cart <= 1.5.3.6 - Sensitive Information Disclosure

high

The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."

CVSS:
7.5
Affected:
up to 1.5.3.6
Fix:
No patched version reported
Disclosed:
Apr 29, 2015

CVE-2015-3302 on NVD →

TheCartPress eCommerce Shopping Cart <= 1.5.3.6 - Multiple Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company, (4...

CVSS:
6.1
Affected:
up to 1.5.3.6
Fix:
No patched version reported
Disclosed:
Apr 29, 2015

CVE-2015-3300 on NVD →

TheCartPress eCommerce Shopping Cart <= 1.5.3.6 - Directory Traversal

medium

Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin...

CVSS:
4.9
Affected:
up to 1.5.3.6
Fix:
No patched version reported
Disclosed:
Apr 29, 2015

CVE-2015-3301 on NVD →

TheCartPress eCommerce Shopping Cart <= 1.5.3.6 Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the tcp_box_p...

CVSS:
8.8
Affected:
up to 1.5.3.6
Fix:
No patched version reported
Disclosed:
Apr 8, 2015

CVE-2015-3986 on NVD →

TheCartPress eCommerce Shopping Cart <= 1.1.5 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter.

CVSS:
6.1
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Dec 31, 2011

CVE-2011-5207 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database