Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 441-460 of 519 records
Threat Entry Updated 2025-06-17

CVE-2023-4826 - Socialdriver Theme

The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site scripting (XSS) attack.

THEME Socialdriver

CVE-2023-4826

MEDIUM CVSS 6.1 2024-02-23
Threat Entry Updated 2024-11-21

CVE-2024-24926 - Creative Multi Purpose Responsive Theme

Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

THEME Creative Multi Purpose Responsive

CVE-2024-24926

HIGH CVSS 7.5 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-24927 - Allows Reflected Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme allows Reflected XSS.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

THEME Allows Reflected Xss

CVE-2024-24927

HIGH CVSS 7.1 2024-02-12
Threat Entry Updated 2024-11-21

CVE-2024-0835 - Royal Elementor Kit Theme

The Royal Elementor Kit theme for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the dismissed_handler function in all versions up to, and including, 1.0.116. This makes it possible for authenticated attackers, with subscriber access or higher, to update arbitrary transients. Note, that these transients can only be updated to true and not arbitrary values.

THEME Royal Elementor Kit

CVE-2024-0835

MEDIUM CVSS 4.3 2024-02-05
Threat Entry Updated 2025-05-30

CVE-2023-7194 - Meris Wp Theme

The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

THEME Meris Wp Theme

CVE-2023-7194

MEDIUM CVSS 6.1 2024-01-22
Threat Entry Updated 2025-05-30

CVE-2024-0679 - Colormag Theme

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins.

THEME Colormag

CVE-2024-0679

MEDIUM CVSS 6.5 2024-01-20
Threat Entry Updated 2025-06-20

CVE-2023-3771 - Through 19 Theme

The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

THEME Through 19

CVE-2023-3771

MEDIUM CVSS 6.1 2024-01-16
Threat Entry Updated 2024-11-21

CVE-2023-6990 - Weaver Xtreme Theme Support

The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions up to, and including, 6.3.0 due to insufficient input sanitization and output escaping on user supplied meta (page-head-code). This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Weaver Xtreme Theme Support

CVE-2023-6990

MEDIUM CVSS 5.4 2024-01-11
Threat Entry Updated 2024-11-21

CVE-2023-50892 - Allows Reflected Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme allows Reflected XSS.This issue affects TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme: from n/a through 5.9.1.

THEME Allows Reflected Xss

CVE-2023-50892

HIGH CVSS 7.1 2023-12-29
Threat Entry Updated 2024-11-21

CVE-2023-51501 - Allows Reflected Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Undsgn Uncode - Creative & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Uncode - Creative & WooCommerce WordPress Theme: from n/a through 2.8.6.

THEME Allows Reflected Xss

CVE-2023-51501

HIGH CVSS 7.1 2023-12-28
Threat Entry Updated 2024-11-21

CVE-2023-6744 - Divi Theme

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Divi

CVE-2023-6744

MEDIUM CVSS 6.4 2023-12-23
Threat Entry Updated 2024-11-21

CVE-2023-49826 - Woocommerce Theme

Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

THEME Woocommerce

CVE-2023-49826

HIGH CVSS 8.1 2023-12-21
Threat Entry Updated 2024-11-21

CVE-2023-29432 - Vulnerability In Favethemes Houzez Real Estate

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Real Estate WordPress Theme: from n/a before 2.8.3.

THEME Vulnerability In Favethemes Houzez Real Estate

CVE-2023-29432

HIGH CVSS 8.2 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-49825 - Woocommerce Theme

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

THEME Woocommerce

CVE-2023-49825

HIGH CVSS 8.5 2023-12-20
Threat Entry Updated 2024-11-21

CVE-2023-49750 - Submitting Coupons Theme

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from n/a before 2.2.

THEME Submitting Coupons

CVE-2023-49750

CRITICAL CVSS 9.3 2023-12-19
Threat Entry Updated 2024-11-21

CVE-2023-49187 - Allows Reflected Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spoonthemes Adifier - Classified Ads WordPress Theme allows Reflected XSS.This issue affects Adifier - Classified Ads WordPress Theme: from n/a before 3.1.4.

THEME Allows Reflected Xss

CVE-2023-49187

HIGH CVSS 7.1 2023-12-15
Threat Entry Updated 2024-11-21

CVE-2023-49827 - Allows Reflected Xss Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

THEME Allows Reflected Xss

CVE-2023-49827

HIGH CVSS 7.1 2023-12-14
Threat Entry Updated 2024-11-21

CVE-2023-5338 - Theme Blvd Shortcodes

The Theme Blvd Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Theme Blvd Shortcodes

CVE-2023-5338

MEDIUM CVSS 6.4 2023-11-22
Threat Entry Updated 2025-02-19

CVE-2023-36529 - Allows Sql Injection Theme

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress Theme: from n/a through 1.3.4.

THEME Allows Sql Injection

CVE-2023-36529

CRITICAL CVSS 9.8 2023-11-03
Scroll to top