GreenMart [greenmart] <= 4.2.11 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart allows PHP Local File Inclusion.This issue affects Greenmart: from n/a through <= 4.2.11.
- Affected:
- up to 4.2.11
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2025
CVE-2025-68983 on NVD →
Greenmart <= 4.2.11 - Authenticated (Contributor+) Local File Inclusion
high
The Greenmart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.11. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 7.5
- Affected:
- up to 4.2.11
- Fix:
- No patched version reported
- Disclosed:
- Dec 20, 2025
CVE-2025-68983 on NVD →
GreenMart [greenmart] < 4.2.4
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart allows PHP Local File Inclusion. This issue affects Greenmart: from n/a through 4.2.3.
- Affected:
- up to 4.2.4
- Fixed in:
- 4.2.4
- Disclosed:
- Jun 27, 2025
CVE-2025-49883 on NVD →
Greenmart <= 4.2.3 - Unauthenticated Local File Inclusion
critical
The Greenmart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.3. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, o...
- CVSS:
- 9.8
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.4
- Disclosed:
- Jun 25, 2025
CVE-2025-49883 on NVD →
Greenmart <= 2.5.1 - Reflected Cross-Site Scripting
medium
The Greenmart theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'callback' parameter in the 'admin-ajax.php' file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...
- CVSS:
- 6.1
- Affected:
- up to 2.5.1
- Fixed in:
- 2.5.2
- Disclosed:
- Oct 29, 2020
GreenMart [greenmart] < 2.5.2
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by ErwanLR (WPScan) in WordPress Greenmart premium theme (versions <= 2.5.1).
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Oct 29, 2020
GreenMart [greenmart] < 2.5.2
unknown
The Greenmart theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'callback' parameter in the 'admin-ajax.php' file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
- Disclosed:
- Oct 29, 2020
GreenMart [greenmart] < 2.4.3
unknown
Reflected Cross-Site Scripting (XSS) vulnerability found by Cyber Security Works Pvt. Ltd in WordPress Greenmart premium theme (versions <= 2.4.2).
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Oct 28, 2020
GreenMart [greenmart] < 2.4.3
unknown
[en] The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Oct 27, 2020
CVE-2020-16140 on NVD →
GreenMart – Organic & Food WooCommerce WordPress Theme < 2.4.3 - Reflected Cross-Site Scripting
medium
The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.
- CVSS:
- 6.1
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Jul 17, 2020
CVE-2020-16140 on NVD →
GreenMart [greenmart] < 2.5.2
unknown
Due to an incomplete fix of CVE-2020-16140 (see https://wpscan.com/vulnerability/10444), the reflected XSS attack is still possible on unauthenticated users, by extracting the search_nonce from the source of the homepage and adding it to the original payload. This is possible because WP nonces are tied to the logged in...
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database