Thecartpress

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 8
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-47932

    WordPress TheCartPress 1.5.3.6 Privilege Escalation Unauthenticated

    Last Modified: Jul 15, 2026
    Published: May 10, 2026

    CVE-2015-4582

    The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.

    Last Modified: Apr 30, 2025
    Published: Apr 28, 2025

    CVE-2024-5938

    Boot Store <= 1.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode

    Last Modified: Apr 08, 2026
    Published: Jul 02, 2024

    CVE-2015-3302

    The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."

    Last Modified: Apr 20, 2025
    Published: Dec 29, 2017

    CVE-2015-3986

    Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.

    Last Modified: Apr 12, 2025
    Published: May 14, 2015
    Items Per Page
    Thecartpress Vulnerabilities & Security CVEs | CVE-DB