Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 361-380 of 519 records
Threat Entry Updated 2024-09-27

CVE-2024-6339 - Phlox Pro Theme

The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions up to, and including, 5.16.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Phlox Pro

CVE-2024-6339

MEDIUM CVSS 6.1 2024-08-21
Threat Entry Updated 2024-09-13

CVE-2023-3409 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'reset_settings' function. This makes it possible for unauthenticated attackers to reset the theme's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Bricks

CVE-2023-3409

MEDIUM CVSS 5.4 2024-08-17
Threat Entry Updated 2024-09-13

CVE-2023-3408 - Bricks Theme

The Bricks theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.1. This is due to missing or incorrect nonce validation on the 'save_settings' function. This makes it possible for unauthenticated attackers to modify the theme's settings, including enabling a setting which allows lower-privileged users such as contributors to perform code execution, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Bricks

CVE-2023-3408

MEDIUM CVSS 4.3 2024-08-17
Threat Entry Updated 2024-08-12

CVE-2024-6639 - Mdx Theme

The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Mdx

CVE-2024-6639

MEDIUM CVSS 6.4 2024-08-12
Threat Entry Updated 2025-03-01

CVE-2024-6987 - Orchid Store Theme

The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Addonify Floating Cart For WooCommerce plugin if it is installed.

THEME Orchid Store

CVE-2024-6987

MEDIUM CVSS 4.3 2024-08-08
Threat Entry Updated 2024-08-08

CVE-2024-7561 - The Next Theme

The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the wpeden_post_meta post meta value. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME The Next

CVE-2024-7561

HIGH CVSS 8.8 2024-08-08
Threat Entry Updated 2024-08-08

CVE-2024-7486 - Multipurpose Theme

The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 via deserialization of untrusted input through the 'wpeden_post_meta' post meta. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME Multipurpose

CVE-2024-7486

HIGH CVSS 8.8 2024-08-08
Threat Entry Updated 2024-08-08

CVE-2024-7560 - News Flash Theme

The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the newsflash_post_meta meta value. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME News Flash

CVE-2024-7560

HIGH CVSS 7.2 2024-08-08
Threat Entry Updated 2024-11-21

CVE-2024-5964 - Zenon Lite Theme

The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Zenon Lite

CVE-2024-5964

MEDIUM CVSS 6.4 2024-07-18
Threat Entry Updated 2024-11-21

CVE-2024-2234 - Before 2 Theme

The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks

THEME Before 2

CVE-2024-2234

MEDIUM CVSS 5.4 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2235 - Before 2 Theme

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, including those they don't have access to via a CSRF attack

THEME Before 2

CVE-2024-2235

MEDIUM CVSS 4.3 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2233 - Before 2 Theme

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. These include declining and accepting group invitations or leaving a group

THEME Before 2

CVE-2024-2233

MEDIUM CVSS 4.3 2024-07-03
Threat Entry Updated 2024-11-21

CVE-2024-2040 - Before 2 Theme

The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users join private groups via a CSRF attack

THEME Before 2

CVE-2024-2040

MEDIUM CVSS 4.3 2024-07-03
Threat Entry Updated 2024-12-26

CVE-2024-5938 - Boot Store Theme

The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Boot Store

CVE-2024-5938

MEDIUM CVSS 6.4 2024-07-02
Threat Entry Updated 2024-11-21

CVE-2024-39310 - Basil Recipe Theme

The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` parameter in versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. Because the of the default WordPress validation, it is not possible to insert the payload directly but if the Cooked plugin is installed, it is possible to create a recipe post…

THEME Basil Recipe

CVE-2024-39310

MEDIUM CVSS 5.4 2024-07-01
Threat Entry Updated 2024-11-21

CVE-2023-4017 - Goya Theme

The Goya theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attra-color’, 'attra-size', and 'product-cata' parameters in versions up to, and including, 1.0.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Goya

CVE-2023-4017

MEDIUM CVSS 6.1 2024-06-29
Threat Entry Updated 2024-11-21

CVE-2024-5925 - Theron Lite Theme

The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Theron Lite

CVE-2024-5925

MEDIUM CVSS 6.4 2024-06-28
Threat Entry Updated 2024-11-21

CVE-2024-5922 - Scylla Lite Theme

The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Scylla Lite

CVE-2024-5922

MEDIUM CVSS 6.4 2024-06-28
Threat Entry Updated 2024-11-21

CVE-2024-5796 - Infinite Theme

The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Infinite

CVE-2024-5796

MEDIUM CVSS 6.4 2024-06-28
Threat Entry Updated 2024-11-21

CVE-2024-5788 - Silesia Theme

The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute within the theme's Button shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Silesia

CVE-2024-5788

MEDIUM CVSS 6.4 2024-06-28
Scroll to top