Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 261-280 of 519 records
Threat Entry Updated 2025-03-05

CVE-2024-13815 - The Listingo Theme

The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

THEME The Listingo

CVE-2024-13815

MEDIUM CVSS 6.5 2025-03-05
Threat Entry Updated 2025-03-05

CVE-2024-13811 - Food Delivery Woocommerce Theme

The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_import_lafka' AJAX actions in all versions up to, and including, 4.5.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo data that overrides the site.

THEME Food Delivery Woocommerce Theme

CVE-2024-13811

MEDIUM CVSS 4.3 2025-03-05
Threat Entry Updated 2025-03-05

CVE-2024-13810 - Zass Woocommerce Theme For Handmade Artists And Artisans

The Zass - WooCommerce Theme for Handmade Artists and Artisans theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'zass_import_zass' AJAX actions in all versions up to, and including, 3.9.9.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo content and overwrite the site.

THEME Zass Woocommerce Theme For Handmade Artists And Artisans

CVE-2024-13810

MEDIUM CVSS 4.3 2025-03-05
Threat Entry Updated 2025-03-05

CVE-2024-13787 - Theme For Wordpress Is Vulnerable To Php Object Injection In All Versions Up To

The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2 via deserialization of untrusted input in the 'veda_backup_and_restore_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin…

THEME Theme For Wordpress Is Vulnerable To Php Object Injection In All Versions Up To

CVE-2024-13787

CRITICAL CVSS 9.8 2025-03-05
Threat Entry Updated 2025-03-05

CVE-2024-8682 - Jnews Wordpress Newspaper Magazine Blog Amp Theme

The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating a user though the register_handler() function. This makes it possible for unauthenticated attackers to register as a user even when user registration is disabled.

THEME Jnews Wordpress Newspaper Magazine Blog Amp Theme

CVE-2024-8682

MEDIUM CVSS 5.3 2025-03-05
Threat Entry Updated 2025-03-05

CVE-2025-1307 - Newscrunch Theme

The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

THEME Newscrunch

CVE-2025-1307

CRITICAL CVSS 9.8 2025-03-04
Threat Entry Updated 2025-03-05

CVE-2025-1306 - Newscrunch Theme

The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the newscrunch_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Newscrunch

CVE-2025-1306

HIGH CVSS 8.8 2025-03-04
Threat Entry Updated 2025-03-05

CVE-2024-13686 - Vw Storefront Theme

The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the themes settings.

THEME Vw Storefront

CVE-2024-13686

MEDIUM CVSS 4.3 2025-03-04
Threat Entry Updated 2025-03-01

CVE-2025-1671 - Academist Membership Theme

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators.

THEME Academist Membership

CVE-2025-1671

CRITICAL CVSS 9.8 2025-03-01
Threat Entry Updated 2025-03-01

CVE-2025-1638 - Alloggio Membership Theme

The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity through the alloggio_membership_init_rest_api_facebook_login and alloggio_membership_init_rest_api_google_login functions. This makes it possible for unauthenticated attackers to log in as any user, including administrators, without knowing a password.

THEME Alloggio Membership

CVE-2025-1638

CRITICAL CVSS 9.8 2025-03-01
Threat Entry Updated 2025-03-01

CVE-2025-1564 - SetSail Membership Theme

The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity through the social login. This makes it possible for unauthenticated attackers to log in as any user, including administrators and take over access to their account.

THEME SetSail Membership

CVE-2025-1564

CRITICAL CVSS 9.8 2025-03-01
Threat Entry Updated 2025-03-01

CVE-2024-12824 - Job Board Wordpress Theme

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the plugin not properly checking for an empty token value prior updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and leverage that to gain access to their account.

THEME Job Board Wordpress Theme

CVE-2024-12824

CRITICAL CVSS 9.8 2025-03-01
Threat Entry Updated 2025-02-28

CVE-2025-1687 - Car Dealer Automotive WordPress Theme – Responsive

The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to update the user email and password via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Car Dealer Automotive WordPress Theme – Responsive

CVE-2025-1687

HIGH CVSS 8.8 2025-02-28
Threat Entry Updated 2025-02-28

CVE-2025-1682 - Car Dealer Automotive WordPress Theme – Responsive

The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the default user role.

THEME Car Dealer Automotive WordPress Theme – Responsive

CVE-2025-1682

HIGH CVSS 8.8 2025-02-28
Threat Entry Updated 2025-02-28

CVE-2024-12811 - Traveler Theme

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_slider' shortcode 'style' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

THEME Traveler

CVE-2024-12811

HIGH CVSS 8.8 2025-02-28
Threat Entry Updated 2025-02-28

CVE-2025-1681 - Car Dealer Automotive WordPress Theme – Responsive

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to change or delete arbitrary css and js files.

THEME Car Dealer Automotive WordPress Theme – Responsive

CVE-2025-1681

MEDIUM CVSS 5.4 2025-02-28
Threat Entry Updated 2025-03-11

CVE-2025-1282 - Responsive Theme

The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_post_photo() and add_car() functions in all versions up to, and including, 1.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The add_car() function may also make it possible to read arbitrary files.

THEME Responsive

CVE-2025-1282

HIGH CVSS 8.8 2025-02-27
Threat Entry Updated 2025-03-11

CVE-2024-2297 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient validation checks placed on the create_autosave AJAX function. This makes it possible for authenticated attackers, with contributor-level access and above, to execute arbitrary PHP code with elevated (administrator-level) privileges. NOTE: Successful exploitation requires (1) the Bricks Builder to be enabled for posts (2) Builder access to be enabled for contributor-level users, and (3) "Code Execution" to be enabled for administrator-level users within the theme's settings.

THEME Bricks

CVE-2024-2297

HIGH CVSS 7.1 2025-02-27
Threat Entry Updated 2025-02-28

CVE-2024-13695 - Enfold Theme

The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

THEME Enfold

CVE-2024-13695

MEDIUM CVSS 6.4 2025-02-25
Threat Entry Updated 2025-02-28

CVE-2024-13693 - Enfold Theme

The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all avia settings which may included sensitive information such as the Mailchimp API Key, reCAPTCHA Secret Key, or Envato private token if they are set.

THEME Enfold

CVE-2024-13693

MEDIUM CVSS 5.3 2025-02-25
Scroll to top