Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 461-480 of 519 records
Threat Entry Updated 2024-11-21

CVE-2023-3965 - Nsc Theme

The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Nsc

CVE-2023-3965

MEDIUM CVSS 6.1 2023-10-20
Threat Entry Updated 2024-11-21

CVE-2023-3962 - Winters Theme

The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Winters

CVE-2023-3962

MEDIUM CVSS 6.1 2023-10-20
Threat Entry Updated 2024-11-21

CVE-2023-3933 - Your Journey Theme

The Your Journey theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

THEME Your Journey

CVE-2023-3933

MEDIUM CVSS 6.1 2023-10-20
Threat Entry Updated 2024-11-21

CVE-2023-5614 - Theme Switcha

The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list' shortcode in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Theme Switcha

CVE-2023-5614

MEDIUM CVSS 6.4 2023-10-20
Threat Entry Updated 2025-04-23

CVE-2023-4971 - Weaver Xtreme Theme Support

The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

THEME Weaver Xtreme Theme Support

CVE-2023-4971

HIGH CVSS 7.2 2023-10-16
Threat Entry Updated 2024-11-21

CVE-2023-2813 - All Of The Above Aapna Theme

All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop WordPress theme before 1.22, Everse WordPress theme before 1.2.4, Fashionable…

THEME All Of The Above Aapna

CVE-2023-2813

MEDIUM CVSS 6.1 2023-09-04
Threat Entry Updated 2024-11-21

CVE-2023-1403 - Weaver Xtreme Theme

The Weaver Xtreme Theme for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 5.0.7. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

THEME Weaver Xtreme Theme

CVE-2023-1403

MEDIUM CVSS 6.4 2023-06-09
Threat Entry Updated 2025-02-04

CVE-2023-0276 - Weaver Xtreme Theme Support

The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

THEME Weaver Xtreme Theme Support

CVE-2023-0276

MEDIUM CVSS 5.4 2023-04-24
Threat Entry Updated 2025-02-06

CVE-2023-0889 - Themeflection Numbers

Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator

THEME Themeflection Numbers

CVE-2023-0889

MEDIUM CVSS 6.5 2023-04-17
Threat Entry Updated 2025-02-19

CVE-2023-0503 - Free Woocommerce Theme 99fy Extension

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

THEME Free Woocommerce Theme 99fy Extension

CVE-2023-0503

MEDIUM CVSS 4.3 2023-03-27
Threat Entry Updated 2024-11-21

CVE-2022-3401 - Bricks Theme

The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulnerability (CVE-2022-3400), makes it possible for authenticated attackers with minimal permissions, such as a subscriber, can edit any page, post, or template on the vulnerable WordPress website and inject a code execution block that can be used to achieve remote code execution.

THEME Bricks

CVE-2022-3401

HIGH CVSS 8.8 2022-10-28
Threat Entry Updated 2024-11-21

CVE-2022-3400 - Bricks Theme

The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.

THEME Bricks

CVE-2022-3400

MEDIUM CVSS 6.5 2022-10-28
Threat Entry Updated 2024-11-21

CVE-2022-3209 - Before 8 Theme

The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

THEME Before 8

CVE-2022-3209

MEDIUM CVSS 6.1 2022-10-10
Threat Entry Updated 2025-06-05

CVE-2022-2654 - Before 2 Theme

The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting

THEME Before 2

CVE-2022-2654

MEDIUM CVSS 6.1 2022-09-16
Threat Entry Updated 2024-11-21

CVE-2022-1251 - Ask Me Theme

The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.

THEME Ask Me

CVE-2022-1251

MEDIUM CVSS 4.3 2022-08-22
Threat Entry Updated 2024-11-21

CVE-2022-2180 - Does Not Properly Validate Uploaded Custom Font Packages Theme

The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).

THEME Does Not Properly Validate Uploaded Custom Font Packages

CVE-2022-2180

CRITICAL CVSS 9.8 2022-08-15
Threat Entry Updated 2024-11-21

CVE-2022-1323 - Before 5 Theme

The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a crafted POST request.

THEME Before 5

CVE-2022-1323

MEDIUM CVSS 6.5 2022-08-08
Threat Entry Updated 2024-11-21

CVE-2022-1951 - Core Plugin For Kitestudio Themes

The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputting them back in a response of an AJAX action, available to both unauthenticated and authenticated users when a premium theme from the vendor is active, leading to a Reflected Cross-Site Scripting.

THEME Core Plugin For Kitestudio Themes

CVE-2022-1951

MEDIUM CVSS 6.1 2022-07-11
Scroll to top