Shapedplugin develops a suite of modestly represented WordPress and WooCommerce plugins spanning tabs, product displays, carousels, and content management features that extend e-commerce and publishing functionality. The recurring vulnerability signal centers on web-application input handling and access control, with exposure clustering around cross-site scripting, cross-site request forgery, authorization bypass, and deserialization flaws—issues typical of server-side plugins operating without strict input validation or privilege boundaries. Defenders should evaluate the prevalence of these plugins in their WordPress deployments and prioritize patches addressing authorization and injection weaknesses; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shapedplugin over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25065HIGH Cross-Site Request Forgery (CSRF) vulnerability in ShapedPlugin WP Tabs – Responsive Tabs Plugin for WordPress plugin <= 2.1.14 versions. | Feb 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-24739HIGH The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Du | Dec 21, 2021 | 8.1 | 26 | NO | NO |
CVE-2025-48134HIGH Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs wp-expand-tabs-free allows Object Injection.This issue affects WP Tabs: from n/a through <= 2.2.12. | May 16, 2025 | 7.2 | 20 | NO | NO |
CVE-2023-0071MEDIUM The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, wh | Jan 30, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-4648MEDIUM The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users w | Jan 16, 2023 | 5.4 | 20 | NO | NO |
CVE-2021-24738MEDIUM The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform | Dec 21, 2021 | 5.4 | 20 | NO | NO |
CVE-2023-0537MEDIUM The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post wher | May 8, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0360MEDIUM The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which | Feb 13, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0097MEDIUM The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post | Jan 30, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-11503MEDIUM The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scri | Mar 25, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shapedplugin.
Media articles that mention a CVE ID that affects a product developed by Shapedplugin — matched by CVE ID, not by vendor name.