TheCartPress maintains an e-commerce shopping-cart platform with a niche but persistent presence in web-based storefronts; vulnerabilities concentrate in the core product and its variants around input-handling and access-control weaknesses endemic to web applications, including cross-site scripting, cross-site request forgery, improper access control, and path-traversal flaws. The vendor's disclosures have a strong tendency to acquire public exploit tooling. Defenders should treat this vendor's advisories as relevant to their e-commerce infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thecartpress over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-3302HIGH The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order det | Dec 29, 2017 | 7.5 | 47 | NO | YES |
CVE-2021-47932CRITICAL WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests | May 10, 2026 | 9.8 | 35 | NO | NO |
CVE-2011-5207MEDIUM Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arb | Oct 4, 2012 | 4.3 | 25 | NO | YES |
CVE-2015-3301MEDIUM Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote ad | May 14, 2015 | 4.0 | 23 | NO | YES |
CVE-2015-3300MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9. | May 14, 2015 | 4.3 | 23 | NO | YES |
CVE-2015-3986MEDIUM Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 al | May 14, 2015 | 4.3 | 22 | NO | YES |
CVE-2015-4582MEDIUM The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product. | Apr 28, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-5938MEDIUM The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, and including, 1 | Jul 2, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thecartpress.
Media articles that mention a CVE ID that affects a product developed by Thecartpress — matched by CVE ID, not by vendor name.