Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

codesupplyco — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting codesupplyco. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Codesupplyco develops WordPress themes and plugins for website customization, with six CVEs recorded to date. Historically, their products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and improper access controls. While no major public security incidents have been documented, their CVE history indicates a pattern of security gaps in user-facing components. The company has addressed vulnerabilities through patches, but the recurrence of similar issues suggests ongoing challenges in secure coding practices. Their position in the WordPress ecosystem makes security updates critical for preventing potential compromises across numerous websites.

CVE ID Title CVSS Severity Published
CVE-2026-11996 Advanced Popups <= 1.2.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field — Advanced Popups CWE-79 6.4 Medium 2026-09-16
CVE-2026-2390 Powerkit <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy Load Image Processing — Powerkit – Supercharge your WordPress Site CWE-79 6.4 Medium 2026-09-07
CVE-2026-28178 WordPress Powerkit plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability — Powerkit CWE-79 6.5 Medium 2026-08-06
CVE-2026-15644 Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute — Powerkit – Supercharge your WordPress Site CWE-79 6.4 Medium 2026-08-01
CVE-2026-15649 Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes — Powerkit – Supercharge your WordPress Site CWE-79 6.4 Medium 2026-08-01
CVE-2026-15645 Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nav' Shortcode Attribute — Powerkit – Supercharge your WordPress Site CWE-79 6.4 Medium 2026-08-01
CVE-2026-39559 WordPress Uppercase theme < 1.2.2 - Local File Inclusion vulnerability — Uppercase CWE-98 8.1 High 2026-06-17
CVE-2026-9629 Canvas <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Block Attribute — Canvas CWE-79 6.4 Medium 2026-06-13
CVE-2025-52723 WordPress Networker theme <= 1.2.0 - Local File Inclusion Vulnerability — Networker CWE-98 8.1 High 2025-06-27
CVE-2024-9025 Sight – Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title — Sight – Professional Image Gallery and Portfolio CWE-862 5.3 Medium 2024-09-26
CVE-2024-2458 Powerkit – Supercharge your WordPress Site <= 2.9.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode — Powerkit – Supercharge your WordPress Site CWE-79 6.4 Medium 2024-04-06
CVE-2024-2962 Networker - Tech News WordPress Theme with Dark Mode <= 1.1.9 - Missing Authorization — Networker - Tech News WordPress Theme with Dark Mode CWE-862 5.3 Medium 2024-03-27
CVE-2021-4426 Absolute Reviews <= 1.0.8 - Cross-Site Request Forgery Bypass — Absolute Reviews CWE-352 4.3 Medium 2023-07-12
CVE-2021-4421 Advanced Popups <= 1.1.1 - Cross-Site Request Forgery Bypass — Advanced Popups CWE-352 4.3 Medium 2023-07-12

This page lists every published CVE security advisory associated with codesupplyco. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.