Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

codesupplyco — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting codesupplyco. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Codesupplyco develops WordPress themes and plugins for website customization, with six CVEs recorded to date. Historically, their products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and improper access controls. While no major public security incidents have been documented, their CVE history indicates a pattern of security gaps in user-facing components. The company has addressed vulnerabilities through patches, but the recurrence of similar issues suggests ongoing challenges in secure coding practices. Their position in the WordPress ecosystem makes security updates critical for preventing potential compromises across numerous websites.

CVE IDTitleCVSSSeverityPublished
CVE-2026-28178 WordPress Powerkit plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability — PowerkitCWE-79 6.5 Medium2026-08-06
CVE-2026-15644 Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute — Powerkit – Supercharge your WordPress SiteCWE-79 6.4 Medium2026-08-01
CVE-2026-15649 Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes — Powerkit – Supercharge your WordPress SiteCWE-79 6.4 Medium2026-08-01
CVE-2026-15645 Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nav' Shortcode Attribute — Powerkit – Supercharge your WordPress SiteCWE-79 6.4 Medium2026-08-01
CVE-2026-39559 WordPress Uppercase theme < 1.2.2 - Local File Inclusion vulnerability — UppercaseCWE-98 8.1 High2026-06-17
CVE-2026-9629 Canvas <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Block Attribute — CanvasCWE-79 6.4 Medium2026-06-13
CVE-2025-52723 WordPress Networker theme <= 1.2.0 - Local File Inclusion Vulnerability — NetworkerCWE-98 8.1 High2025-06-27
CVE-2024-9025 Sight – Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title — Sight – Professional Image Gallery and PortfolioCWE-862 5.3 Medium2024-09-26
CVE-2024-2458 Powerkit – Supercharge your WordPress Site <= 2.9.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode — Powerkit – Supercharge your WordPress SiteCWE-79 6.4 Medium2024-04-06
CVE-2024-2962 Networker - Tech News WordPress Theme with Dark Mode <= 1.1.9 - Missing Authorization — Networker - Tech News WordPress Theme with Dark ModeCWE-862 5.3 Medium2024-03-27
CVE-2021-4426 Absolute Reviews <= 1.0.8 - Cross-Site Request Forgery Bypass — Absolute ReviewsCWE-352 4.3 Medium2023-07-12
CVE-2021-4421 Advanced Popups <= 1.1.1 - Cross-Site Request Forgery Bypass — Advanced PopupsCWE-352 4.3 Medium2023-07-12

This page lists every published CVE security advisory associated with codesupplyco. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.