Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 421-440 of 519 records
Threat Entry Updated 2025-01-31

CVE-2024-2340 - Avada Theme

The Avada theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.11.6 via the '/wp-content/uploads/fusion-forms/' directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via an Avada created form with a file upload mechanism.

THEME Avada

CVE-2024-2340

MEDIUM CVSS 5.3 2024-04-09
Threat Entry Updated 2025-02-05

CVE-2024-2311 - Avada Theme

The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Avada

CVE-2024-2311

MEDIUM CVSS 6.4 2024-04-09
Threat Entry Updated 2024-11-21

CVE-2024-1984 - Graphene Theme

The Graphene theme for WordPress is vulnerable to unauthorized access of data via meta tag in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated individuals to obtain post contents of password protected posts via the generated source.

THEME Graphene

CVE-2024-1984

MEDIUM CVSS 5.3 2024-04-09
Threat Entry Updated 2025-09-30

CVE-2024-1587 - Newsmatic Theme

The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filter_posts_load_tab_content'. This makes it possible for unauthenticated attackers to view draft posts and post content.

THEME Newsmatic

CVE-2024-1587

MEDIUM CVSS 5.3 2024-04-09
Threat Entry Updated 2025-05-06

CVE-2023-6695 - Beaver Themer

The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including arbitrary user_meta values.

THEME Beaver Themer

CVE-2023-6695

MEDIUM CVSS 6.5 2024-04-09
Threat Entry Updated 2025-05-06

CVE-2023-6694 - Beaver Themer

The Beaver Themer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied custom fields. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Beaver Themer

CVE-2023-6694

MEDIUM CVSS 6.4 2024-04-09
Threat Entry Updated 2024-11-21

CVE-2024-2848 - Responsive Theme

The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_footer_text_callback function in all versions up to, and including, 5.0.2. This makes it possible for unauthenticated attackers to inject arbitrary HTML content into the site's footer.

THEME Responsive

CVE-2024-2848

HIGH CVSS 7.5 2024-03-29
Threat Entry Updated 2024-11-21

CVE-2024-2476 - Oceanwp Theme

The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_theme_panel_pane function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose sensitive information such as system/environment data and API keys.

THEME Oceanwp

CVE-2024-2476

MEDIUM CVSS 4.3 2024-03-29
Threat Entry Updated 2024-11-21

CVE-2024-2962 - Networker - Tech News WordPress Theme with Dark Mode

The Networker - Tech News WordPress Theme with Dark Mode theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_reload_nav_menu() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to modify the location of display menus.

THEME Networker - Tech News WordPress Theme with Dark Mode

CVE-2024-2962

MEDIUM CVSS 5.3 2024-03-27
Threat Entry Updated 2024-11-21

CVE-2024-2025 - buddypress_woocommerce_my_account_integration Theme

The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.20 via deserialization of untrusted input in the get_simple_request function. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

THEME buddypress_woocommerce_my_account_integration

CVE-2024-2025

HIGH CVSS 8.8 2024-03-23
Threat Entry Updated 2024-11-21

CVE-2024-2500 - Colormag Theme

The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authentciated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Colormag

CVE-2024-2500

MEDIUM CVSS 6.4 2024-03-22
Threat Entry Updated 2024-11-21

CVE-2024-2252 - Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder Theme

The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping on user supplied attributes such as URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder

CVE-2024-2252

MEDIUM CVSS 5.4 2024-03-13
Threat Entry Updated 2025-01-31

CVE-2024-1668 - Woocommerce Theme

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's "password" field).

THEME Woocommerce

CVE-2024-1668

MEDIUM CVSS 6.5 2024-03-13
Threat Entry Updated 2025-01-22

CVE-2024-2107 - Blossom Spa Theme

The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.4 via generated source. This makes it possible for unauthenticated attackers to extract sensitive data including contents of password-protected or scheduled posts.

THEME Blossom Spa

CVE-2024-2107

MEDIUM CVSS 5.8 2024-03-12
Threat Entry Updated 2025-02-04

CVE-2024-1767 - Blocksy Theme

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.0.26 due to insufficient input sanitization and output escaping on user supplied attributes like 'className' and 'radius'. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Blocksy

CVE-2024-1767

MEDIUM CVSS 6.4 2024-03-09
Threat Entry Updated 2025-03-11

CVE-2024-1771 - Total Theme

The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the total_order_sections() function in all versions up to, and including, 2.1.59. This makes it possible for authenticated attackers, with subscriber-level access and above, to repeat sections on the homepage.

THEME Total

CVE-2024-1771

MEDIUM CVSS 5.3 2024-03-06
Threat Entry Updated 2025-02-05

CVE-2024-1468 - Woocommerce Theme

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated attackers, with contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

THEME Woocommerce

CVE-2024-1468

HIGH CVSS 8.8 2024-02-29
Threat Entry Updated 2025-01-08

CVE-2024-1943 - Yuki Theme

The Yuki theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 1.3.14. This is due to missing or incorrect nonce validation on the reset_customizer_options() function. This makes it possible for unauthenticated attackers to reset the themes settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Yuki

CVE-2024-1943

MEDIUM CVSS 4.3 2024-02-28
Threat Entry Updated 2025-01-16

CVE-2024-1388 - Yuki Theme

The Yuki theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_customizer_options() function in all versions up to, and including, 1.3.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to reset the theme's settings.

THEME Yuki

CVE-2024-1388

MEDIUM CVSS 4.3 2024-02-28
Threat Entry Updated 2025-02-05

CVE-2024-1360 - Colibri Wp Theme

The Colibri WP theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.94. This is due to missing or incorrect nonce validation on the colibriwp_install_plugin() function. This makes it possible for unauthenticated attackers to install recommended plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

THEME Colibri Wp

CVE-2024-1360

MEDIUM CVSS 4.3 2024-02-23
Scroll to top