Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High2
Medium2
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2025-02-21

CVE-2024-13681 - Uncode Plugin

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for unauthenticated attackers to read arbitrary files on the server.

PLUGIN Uncode

CVE-2024-13681

HIGH CVSS 7.5 2025-02-18
Threat Entry Updated 2025-02-21

CVE-2024-13691 - Uncode Plugin

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the server.

PLUGIN Uncode

CVE-2024-13691

MEDIUM CVSS 6.5 2025-02-18
Threat Entry Updated 2025-02-21

CVE-2024-13667 - Uncode Plugin

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Uncode

CVE-2024-13667

MEDIUM CVSS 5.4 2025-02-18
Threat Entry Updated 2024-11-21

CVE-2023-51501 - Uncode Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Undsgn Uncode - Creative & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Uncode - Creative & WooCommerce WordPress Theme: from n/a through 2.8.6.

PLUGIN Uncode

CVE-2023-51501

HIGH CVSS 7.1 2023-12-28
Scroll to top