Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 281-300 of 519 records
Threat Entry Updated 2025-02-19

CVE-2025-1065 - Visualizer: Tables and Charts Manager for WordPress Theme

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Visualizer: Tables and Charts Manager for WordPress

CVE-2025-1065

MEDIUM CVSS 6.4 2025-02-19
Threat Entry Updated 2025-02-18

CVE-2025-27013 - MediCenter - Health Medical Clinic WordPress Theme

Missing Authorization vulnerability in EPC MediCenter - Health Medical Clinic WordPress Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MediCenter - Health Medical Clinic WordPress Theme: from n/a through n/a.

THEME MediCenter - Health Medical Clinic WordPress Theme

CVE-2025-27013

MEDIUM CVSS 5.3 2025-02-18
Threat Entry Updated 2025-02-21

CVE-2024-13681 - Uncode Theme

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for unauthenticated attackers to read arbitrary files on the server.

THEME Uncode

CVE-2024-13681

HIGH CVSS 7.5 2025-02-18
Threat Entry Updated 2025-02-21

CVE-2024-13797 - Pressmart Modern Elementor Woocommerce Wordpress Theme

The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

THEME Pressmart Modern Elementor Woocommerce Wordpress Theme

CVE-2024-13797

HIGH CVSS 7.3 2025-02-18
Threat Entry Updated 2025-02-21

CVE-2024-13691 - Uncode Theme

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the server.

THEME Uncode

CVE-2024-13691

MEDIUM CVSS 6.5 2025-02-18
Threat Entry Updated 2025-02-21

CVE-2024-13667 - Uncode Theme

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Uncode

CVE-2024-13667

MEDIUM CVSS 5.4 2025-02-18
Threat Entry Updated 2025-02-21

CVE-2024-12860 - Dealership Wordpress Classified Theme

The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

THEME Dealership Wordpress Classified Theme

CVE-2024-12860

CRITICAL CVSS 9.8 2025-02-18
Threat Entry Updated 2025-05-21

CVE-2024-13726 - Themes Coder

The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

THEME Themes Coder

CVE-2024-13726

HIGH CVSS 8.6 2025-02-17
Threat Entry Updated 2025-02-18

CVE-2024-13867 - Listivo Classified Ads Wordpress Theme

The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 2.3.67 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Listivo Classified Ads Wordpress Theme

CVE-2024-13867

MEDIUM CVSS 6.1 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2025-0661 - Dethemekit For Elementor

The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, draft, or scheduled posts that they should not have access to by duplicating the post.

THEME Dethemekit For Elementor

CVE-2025-0661

MEDIUM CVSS 4.3 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2024-13346 - Woocommerce Theme

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

THEME Woocommerce

CVE-2024-13346

HIGH CVSS 7.3 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2024-13770 - Rtl Theme

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of untrusted input 'view_more_posts' AJAX action. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional…

THEME Rtl

CVE-2024-13770

HIGH CVSS 8.1 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2025-0837 - Puzzles Theme

The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Puzzles

CVE-2025-0837

MEDIUM CVSS 6.4 2025-02-13
Threat Entry Updated 2025-11-13

CVE-2024-10763 - Campress Theme

The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

THEME Campress

CVE-2024-10763

CRITICAL CVSS 9.8 2025-02-13
Threat Entry Updated 2025-02-25

CVE-2024-13644 - Dethemekit For Elementor

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Dethemekit For Elementor

CVE-2024-13644

MEDIUM CVSS 6.4 2025-02-13
Threat Entry Updated 2025-02-24

CVE-2024-13656 - Blog Theme

The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.6.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to legitimate users.

THEME Blog Theme

CVE-2024-13656

HIGH CVSS 8.1 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13769 - Rtl Theme

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the 'theme_options_ajax_post_action' AJAX action in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings and inject malicious web scripts. The developer opted to remove the software from the repository, so an update is not available and it is recommended to find a replacement software.

THEME Rtl

CVE-2024-13769

MEDIUM CVSS 6.4 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13421 - For Wordpress Is Vulnerable To Privilege Escalation In All Versions Up To Theme

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles allowed to be selected during registration. This makes it possible for unauthenticated attackers to register a new administrative user account.

THEME For Wordpress Is Vulnerable To Privilege Escalation In All Versions Up To

CVE-2024-13421

CRITICAL CVSS 9.8 2025-02-12
Threat Entry Updated 2025-02-25

CVE-2024-13653 - Zoxpress The All In One Wordpress News Theme

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' function in all versions up to, and including, 2.12.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

THEME Zoxpress The All In One Wordpress News Theme

CVE-2024-13653

HIGH CVSS 8.8 2025-02-12
Threat Entry Updated 2025-02-24

CVE-2024-13654 - Zoxpress The All In One Wordpress News Theme

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'reset_options' function in all versions up to, and including, 2.12.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to legitimate users.

THEME Zoxpress The All In One Wordpress News Theme

CVE-2024-13654

HIGH CVSS 8.1 2025-02-12
Scroll to top