
ShopRite
A registered trademark of retailer-owned cooperative Wakefern Food Corp., ShopRite serves more than 6 million customers via more than 250 ShopRite locations throughout NJ, NY, PA, CT, DE & MD



A registered trademark of retailer-owned cooperative Wakefern Food Corp., ShopRite serves more than 6 million customers via more than 250 ShopRite locations throughout NJ, NY, PA, CT, DE & MD

The Kraft Heinz Company is one of the largest food and beverage companies in the world, with eight $1 billion+ brands and global sales of approximately $25 billion. We’re a globally trusted producer of high-quality, great-tasting, and nutritious foods for over 150 years. While Kraft Heinz is co-headquartered in Chicago and Pittsburgh, our brands are truly global, with products produced and marketed in over 40 countries. These beloved products include condiments and sauces, cheese and dairy, meals, meats, refreshment beverages, coffee, infant and nutrition products, and numerous other grocery products in a portfolio of more than 200 legacy and emerging brands. We spark joy around mealtime with our iconic brands, including Kraft, Oscar Mayer, Heinz, Philadelphia, Lunchables, Velveeta, Maxwell House, Capri Sun, Ore-Ida, Kool-Aid, Jell-O, Primal Kitchen, and Classico, among others. No matter the brand, we’re united under one vision: To sustainably grow by delighting more consumers globally. Bringing this vision to life is our team of 37,000+ food lovers, creative thinkers, and high performers worldwide. Together, we help provide meals to those in need through our global partnership with Rise Against Hunger. We also stand committed to responsible, sustainable practices that extend to every facet of our business, our consumers, and our communities. Every day, we’re transforming the food industry with bold thinking and unprecedented results. If you share our passion – and are ready to create the future, build a legacy, and lead as a global citizen – there’s only one thing to do: join our table and let’s make life delicious!
Security & Compliance Standards Overview












No incidents recorded for ShopRite in 2026.
No incidents recorded for Kraft Heinz in 2026.
ShopRite cyber incidents detection timeline including parent company and subsidiaries
Kraft Heinz cyber incidents detection timeline including parent company and subsidiaries
Last 3 Security & Risk Events by Company
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘options’ parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NOTE: Successful exploitation of this vulnerability requires that the PDFCrowd API key is blank (also known as "demo mode", which is the default configuration when the plugin is installed) or known.
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires an admin to grant Hustle module permissions (or module edit access) to the low-privileged user so they can access the Hustle admin page and obtain the required nonce.
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.
The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.