Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total471
Critical68
High135
Medium268
Reset
Showing 301-320 of 471 records
Threat Entry Updated 2024-10-02

CVE-2024-8515 - Themesflat Addons For Elementor

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Themesflat Addons For Elementor

CVE-2024-8515

MEDIUM CVSS 6.4 2024-09-25
Threat Entry Updated 2024-09-27

CVE-2023-3410 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up to, and including, 1.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the Bricks Builder (admin-only by default), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This becomes more of an issue when Bricks Builder access is granted to lower-privileged users.

THEME Bricks

CVE-2023-3410

MEDIUM CVSS 5.4 2024-09-14
Threat Entry Updated 2024-09-26

CVE-2024-5884 - Beauty Theme

The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Beauty

CVE-2024-5884

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-26

CVE-2024-5870 - Tweaker5 Theme

The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Tweaker5

CVE-2024-5870

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-27

CVE-2024-5869 - Neighborly Theme

The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Neighborly

CVE-2024-5869

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-26

CVE-2024-5867 - Delicate Theme

The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme's Button shortcode in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Delicate

CVE-2024-5867

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-26

CVE-2024-5789 - Triton Lite Theme

The Triton Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the theme's Button shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Triton Lite

CVE-2024-5789

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-26

CVE-2024-5567 - Betheme

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

THEME Betheme

CVE-2024-5567

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2025-07-10

CVE-2024-7435 - Attire Theme

The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME Attire

CVE-2024-7435

HIGH CVSS 8.8 2024-08-31
Threat Entry Updated 2024-09-03

CVE-2024-2694 - Betheme

The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME Betheme

CVE-2024-2694

HIGH CVSS 8.8 2024-08-30
Threat Entry Updated 2024-09-03

CVE-2024-3998 - Betheme

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Betheme

CVE-2024-3998

MEDIUM CVSS 6.4 2024-08-30
Threat Entry Updated 2024-09-03

CVE-2024-5061 - Enfold Responsive Multi Purpose Theme

The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' parameters in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Enfold Responsive Multi Purpose Theme

CVE-2024-5061

MEDIUM CVSS 6.4 2024-08-30
Threat Entry Updated 2024-09-27

CVE-2024-6339 - Phlox Pro Theme

The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions up to, and including, 5.16.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Phlox Pro

CVE-2024-6339

MEDIUM CVSS 6.1 2024-08-21
Threat Entry Updated 2024-09-13

CVE-2023-3409 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'reset_settings' function. This makes it possible for unauthenticated attackers to reset the theme's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Bricks

CVE-2023-3409

MEDIUM CVSS 5.4 2024-08-17
Threat Entry Updated 2024-09-13

CVE-2023-3408 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' function. This makes it possible for unauthenticated attackers to modify the theme's settings, including enabling a setting which allows lower-privileged users such as contributors to perform code execution, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Bricks

CVE-2023-3408

MEDIUM CVSS 4.3 2024-08-17
Threat Entry Updated 2024-08-12

CVE-2024-6639 - Mdx Theme

The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Mdx

CVE-2024-6639

MEDIUM CVSS 6.4 2024-08-12
Threat Entry Updated 2025-03-01

CVE-2024-6987 - Orchid Store Theme

The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Addonify Floating Cart For WooCommerce plugin if it is installed.

THEME Orchid Store

CVE-2024-6987

MEDIUM CVSS 4.3 2024-08-08
Threat Entry Updated 2024-08-08

CVE-2024-7561 - The Next Theme

The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the wpeden_post_meta post meta value. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME The Next

CVE-2024-7561

HIGH CVSS 8.8 2024-08-08
Threat Entry Updated 2024-08-08

CVE-2024-7486 - Multipurpose Theme

The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 via deserialization of untrusted input through the 'wpeden_post_meta' post meta. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME Multipurpose

CVE-2024-7486

HIGH CVSS 8.8 2024-08-08
Threat Entry Updated 2024-08-08

CVE-2024-7560 - News Flash Theme

The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the newsflash_post_meta meta value. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME News Flash

CVE-2024-7560

HIGH CVSS 7.2 2024-08-08
Scroll to top