Skip to content

Known CVE

Themes Coder Ecommerce <= 1.3.4 - SQL Injection

The Themes Coder Ecommerce WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-13726

High2024CVSS 8.6CWE-89

wpscan · cve2024 · wp · wordpress · wp-plugin · sqli · tc-ecommerce · timebased-sqli

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website