Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 301-320 of 519 records
Threat Entry Updated 2025-02-11

CVE-2025-0169 - Is Vulnerable To Stored Cross Site Scripting Via Shortcodes In Versions Up To Theme

The DWT - Directory & Listing WordPress Theme is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Is Vulnerable To Stored Cross Site Scripting Via Shortcodes In Versions Up To

CVE-2025-0169

MEDIUM CVSS 6.4 2025-02-08
Threat Entry Updated 2025-02-04

CVE-2024-13529 - Socialv Social Network And Community Buddypress Theme

The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'socialv_send_download_file' function in all versions up to, and including, 2.0.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download arbitrary files from the target system.

THEME Socialv Social Network And Community Buddypress Theme

CVE-2024-13529

MEDIUM CVSS 6.5 2025-02-04
Threat Entry Updated 2025-02-24

CVE-2024-13547 - Athemes Addons For Elementor

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Athemes Addons For Elementor

CVE-2024-13547

MEDIUM CVSS 6.4 2025-02-01
Threat Entry Updated 2025-02-04

CVE-2024-10847 - Storely Theme

The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 16.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Storely

CVE-2024-10847

MEDIUM CVSS 6.4 2025-01-30
Threat Entry Updated 2025-02-04

CVE-2024-11936 - Zox News Theme

The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

THEME Zox News

CVE-2024-11936

HIGH CVSS 8.8 2025-01-26
Threat Entry Updated 2025-01-24

CVE-2025-24666 - AI Chatbot for WordPress – Hyve Lite Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeIsle AI Chatbot for WordPress – Hyve Lite allows Stored XSS. This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 1.2.2.

THEME AI Chatbot for WordPress – Hyve Lite

CVE-2025-24666

MEDIUM CVSS 5.9 2025-01-24
Threat Entry Updated 2025-02-07

CVE-2024-13698 - Jobify Job Board Wordpress Theme

The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'download_image_via_ai' and 'generate_image_via_ai' functions in all versions up to, and including, 4.2.7. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application to upload files in an image format, and to generate AI images using the site's OpenAI key.

THEME Jobify Job Board Wordpress

CVE-2024-13698

MEDIUM CVSS 6.5 2025-01-24
Threat Entry Updated 2025-02-04

CVE-2024-10324 - Romethemekit For Elementor

The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function in widgets/offcanvas-rometheme.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

THEME Romethemekit For Elementor

CVE-2024-10324

MEDIUM CVSS 4.3 2025-01-24
Threat Entry Updated 2025-02-05

CVE-2024-13545 - Bootstrap Ultimate Theme

The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included. If php://filter is enabled on the server, this issue may directly lead to Remote Code Execution.

THEME Bootstrap Ultimate

CVE-2024-13545

CRITICAL CVSS 9.8 2025-01-24
Threat Entry Updated 2025-01-24

CVE-2024-12857 - Adforest Theme

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.

THEME Adforest

CVE-2024-12857

CRITICAL CVSS 9.8 2025-01-22
Threat Entry Updated 2025-06-05

CVE-2025-0450 - Betheme

The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality in all versions up to, and including, 27.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Betheme

CVE-2025-0450

MEDIUM CVSS 6.4 2025-01-21
Threat Entry Updated 2025-01-18

CVE-2025-0515 - Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme

The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cmsmasters_hide_admin_notice' function in all versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 'hide' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service…

THEME Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme

CVE-2025-0515

MEDIUM CVSS 4.3 2025-01-18
Threat Entry Updated 2025-01-16

CVE-2025-0170 - DWT - Directory & Listing WordPress Theme

The DWT - Directory & Listing WordPress Theme is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping on the 'sort_by' and 'token' parameters. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME DWT - Directory & Listing WordPress Theme

CVE-2025-0170

MEDIUM CVSS 6.1 2025-01-16
Threat Entry Updated 2025-08-12

CVE-2024-11350 - Adforest Theme

The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

THEME Adforest

CVE-2024-11350

CRITICAL CVSS 9.8 2025-01-08
Threat Entry Updated 2025-08-12

CVE-2024-12855 - Adforest Theme

The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in all versions up to, and including, 5.1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete posts, attachments and deactivate a license.

THEME Adforest

CVE-2024-12855

MEDIUM CVSS 4.3 2025-01-08
Threat Entry Updated 2025-03-06

CVE-2024-12205 - Themesflat Addons For Elementor

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Themesflat Addons For Elementor

CVE-2024-12205

MEDIUM CVSS 6.4 2025-01-08
Threat Entry Updated 2025-01-07

CVE-2024-12202 - Croma Theme

The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'ironMusic_ajax' function in all versions up to, and including, 3.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

THEME Croma

CVE-2024-12202

HIGH CVSS 8.8 2025-01-07
Threat Entry Updated 2025-01-07

CVE-2024-12781 - Woocommerce Shopping Theme

The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'lab_1cl_demo_install_package_content' function in all versions up to, and including, 4.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite content with imported demo content.

THEME Woocommerce Shopping Theme

CVE-2024-12781

MEDIUM CVSS 4.3 2025-01-07
Threat Entry Updated 2025-05-22

CVE-2024-12588 - Shortcodes And Extra Features For Phlox Theme

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Staff widget in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Shortcodes And Extra Features For Phlox Theme

CVE-2024-12588

MEDIUM CVSS 6.4 2024-12-21
Threat Entry Updated 2025-05-22

CVE-2024-9545 - Shortcodes And Extra Features For Phlox Theme

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aux_contact_box and aux_gmaps shortcodes in all versions up to, and including, 2.16.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Shortcodes And Extra Features For Phlox Theme

CVE-2024-9545

MEDIUM CVSS 6.4 2024-12-21
Scroll to top