Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 341-360 of 519 records
Threat Entry Updated 2024-11-26

CVE-2024-9775 - Anih Creative Agency Wordpress Theme

The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2024 due to an incomplete blacklist, insufficient input sanitization, and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

THEME Anih Creative Agency Wordpress Theme

CVE-2024-9775

MEDIUM CVSS 5.5 2024-11-09
Threat Entry Updated 2024-11-06

CVE-2024-51682 - Builder For Elementor Allows Stored Xss Theme

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor allows Stored XSS.This issue affects HT Builder – WordPress Theme Builder for Elementor: from n/a through 1.3.0.

THEME Builder For Elementor Allows Stored Xss

CVE-2024-51682

MEDIUM CVSS 6.5 2024-11-04
Threat Entry Updated 2024-10-25

CVE-2024-10250 - Nioland Theme

The Nioland theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Nioland

CVE-2024-10250

MEDIUM CVSS 6.1 2024-10-23
Threat Entry Updated 2025-05-22

CVE-2024-8486 - Shortcodes And Extra Features For Phlox Theme

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Shortcodes And Extra Features For Phlox Theme

CVE-2024-8486

MEDIUM CVSS 6.4 2024-10-05
Threat Entry Updated 2024-11-13

CVE-2024-7434 - Ultrapress Theme

The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME Ultrapress

CVE-2024-7434

HIGH CVSS 8.8 2024-10-01
Threat Entry Updated 2024-11-13

CVE-2024-7433 - Empowerment Theme

The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME Empowerment

CVE-2024-7433

HIGH CVSS 8.8 2024-10-01
Threat Entry Updated 2024-11-13

CVE-2024-7432 - Unseen Blog Theme

The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME Unseen Blog

CVE-2024-7432

HIGH CVSS 8.8 2024-10-01
Threat Entry Updated 2024-10-02

CVE-2024-8516 - Themesflat Addons For Elementor

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and future scheduled posts.

THEME Themesflat Addons For Elementor

CVE-2024-8516

MEDIUM CVSS 4.3 2024-09-25
Threat Entry Updated 2024-10-02

CVE-2024-8515 - Themesflat Addons For Elementor

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Themesflat Addons For Elementor

CVE-2024-8515

MEDIUM CVSS 6.4 2024-09-25
Threat Entry Updated 2024-09-27

CVE-2023-3410 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘customTag' attribute in versions up to, and including, 1.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the Bricks Builder (admin-only by default), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This becomes more of an issue when Bricks Builder access is granted to lower-privileged users.

THEME Bricks

CVE-2023-3410

MEDIUM CVSS 5.4 2024-09-14
Threat Entry Updated 2024-09-26

CVE-2024-5884 - Beauty Theme

The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Beauty

CVE-2024-5884

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-26

CVE-2024-5870 - Tweaker5 Theme

The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Tweaker5

CVE-2024-5870

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-27

CVE-2024-5869 - Neighborly Theme

The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Neighborly

CVE-2024-5869

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-26

CVE-2024-5867 - Delicate Theme

The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme's Button shortcode in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Delicate

CVE-2024-5867

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-26

CVE-2024-5789 - Triton Lite Theme

The Triton Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the theme's Button shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Triton Lite

CVE-2024-5789

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2024-09-26

CVE-2024-5567 - Betheme

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

THEME Betheme

CVE-2024-5567

MEDIUM CVSS 6.4 2024-09-13
Threat Entry Updated 2025-07-10

CVE-2024-7435 - Attire Theme

The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME Attire

CVE-2024-7435

HIGH CVSS 8.8 2024-08-31
Threat Entry Updated 2024-09-03

CVE-2024-2694 - Betheme

The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME Betheme

CVE-2024-2694

HIGH CVSS 8.8 2024-08-30
Threat Entry Updated 2024-09-03

CVE-2024-3998 - Betheme

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Betheme

CVE-2024-3998

MEDIUM CVSS 6.4 2024-08-30
Threat Entry Updated 2024-09-03

CVE-2024-5061 - Enfold Responsive Multi Purpose Theme

The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' parameters in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Enfold Responsive Multi Purpose Theme

CVE-2024-5061

MEDIUM CVSS 6.4 2024-08-30
Scroll to top