Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 321-340 of 519 records
Threat Entry Updated 2025-08-12

CVE-2024-11349 - Adforest Theme

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.

THEME Adforest

CVE-2024-11349

CRITICAL CVSS 9.8 2024-12-21
Threat Entry Updated 2024-12-18

CVE-2024-11926 - Travel Booking Wordpress Theme

The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '__stPartnerCreateServiceRental', 'st_delete_order_item', '_st_partner_approve_booking', 'save_order_item', and '__userDenyEachInfo' functions in all versions up to, and including, 3.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify posts, delete posts and pages, approve arbitrary orders, insert orders with arbitrary prices, and deny user information.

THEME Travel Booking Wordpress Theme

CVE-2024-11926

MEDIUM CVSS 6.5 2024-12-18
Threat Entry Updated 2024-12-18

CVE-2024-11912 - Travel Booking Wordpress Theme

The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id’ parameter in all versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

THEME Travel Booking Wordpress Theme

CVE-2024-11912

HIGH CVSS 7.5 2024-12-18
Threat Entry Updated 2024-12-12

CVE-2024-12333 - Woodmart Theme

The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_instagram_ajax_query AJAX action. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

THEME Woodmart

CVE-2024-12333

MEDIUM CVSS 6.5 2024-12-12
Threat Entry Updated 2024-12-06

CVE-2024-11289 - Soledad Theme

The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penci_more_post_ajax_func, and penci_more_featured_post_ajax_func. This makes it possible for unauthenticated attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included. The exploitability of this is limited to Windows.

THEME Soledad

CVE-2024-11289

HIGH CVSS 8.1 2024-12-06
Threat Entry Updated 2024-12-06

CVE-2024-10849 - Newsmash Theme

The NewsMash theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 1.0.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Newsmash

CVE-2024-10849

MEDIUM CVSS 6.4 2024-12-06
Threat Entry Updated 2024-12-06

CVE-2024-10578 - Pubnews Theme

The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pubnews_importer_plugin_action_for_notice() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins that can be leveraged to exploit other vulnerabilities.

THEME Pubnews

CVE-2024-10578

HIGH CVSS 8.8 2024-12-06
Threat Entry Updated 2024-12-06

CVE-2024-10836 - Flixita Theme

The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.82 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Flixita

CVE-2024-10836

MEDIUM CVSS 6.1 2024-12-06
Threat Entry Updated 2025-02-03

CVE-2024-11420 - Blocksy Theme

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter in all versions up to, and including, 2.0.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Blocksy

CVE-2024-11420

MEDIUM CVSS 6.4 2024-12-05
Threat Entry Updated 2024-12-05

CVE-2024-10848 - Newsmunch Theme

The NewsMunch theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 1.0.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Newsmunch

CVE-2024-10848

MEDIUM CVSS 6.4 2024-12-05
Threat Entry Updated 2025-02-10

CVE-2024-52478 - Allows Stored Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ben Marshall Jobify - Job Board WordPress Theme allows Stored XSS.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.

THEME Allows Stored Xss

CVE-2024-52478

MEDIUM CVSS 6.5 2024-12-02
Threat Entry Updated 2025-02-10

CVE-2024-52479 - Allows Cross Site Request Forgery Theme

Cross-Site Request Forgery (CSRF) vulnerability in Ben Marshall Jobify - Job Board WordPress Theme allows Cross Site Request Forgery.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.

THEME Allows Cross Site Request Forgery

CVE-2024-52479

MEDIUM CVSS 4.3 2024-12-02
Threat Entry Updated 2025-02-10

CVE-2024-52481 - Allows Relative Path Traversal Theme

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify - Job Board WordPress Theme allows Relative Path Traversal.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.

THEME Allows Relative Path Traversal

CVE-2024-52481

HIGH CVSS 7.5 2024-11-28
Threat Entry Updated 2024-11-21

CVE-2024-10623 - Forumengine Theme

The ForumEngine theme for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Forumengine

CVE-2024-10623

MEDIUM CVSS 6.1 2024-11-21
Threat Entry Updated 2024-11-19

CVE-2024-9830 - Bard Theme

The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.216. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Bard

CVE-2024-9830

MEDIUM CVSS 6.1 2024-11-19
Threat Entry Updated 2024-11-29

CVE-2024-9777 - Ashe Theme

The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.243. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Ashe

CVE-2024-9777

MEDIUM CVSS 6.1 2024-11-19
Threat Entry Updated 2025-12-23

CVE-2024-10470 - Wordpress Lms Theme

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.

THEME Wordpress Lms

CVE-2024-10470

CRITICAL CVSS 9.8 2024-11-09
Threat Entry Updated 2024-11-12

CVE-2024-10674 - Th Shop Mania Theme

The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins which can be leveraged to exploit other vulnerabilities and achieve remote code execution and privilege escalation.

THEME Th Shop Mania

CVE-2024-10674

HIGH CVSS 8.8 2024-11-09
Threat Entry Updated 2024-11-12

CVE-2024-10673 - Top Store Theme

The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution.

THEME Top Store

CVE-2024-10673

HIGH CVSS 8.8 2024-11-09
Scroll to top