Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total519
Critical73
High150
Medium296
Reset
Showing 481-500 of 519 records
Threat Entry Updated 2024-11-21

CVE-2022-1424 - Ask Me Theme

The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

THEME Ask Me

CVE-2022-1424

MEDIUM CVSS 6.5 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1422 - Before 5 Theme

The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.

THEME Before 5

CVE-2022-1422

MEDIUM CVSS 6.5 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1241 - Ask Me Theme

The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues

THEME Ask Me

CVE-2022-1241

MEDIUM CVSS 6.1 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2022-1421 - Before 5 Theme

The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack

THEME Before 5

CVE-2022-1421

MEDIUM CVSS 4.3 2022-06-08
Threat Entry Updated 2024-11-21

CVE-2021-24982 - Child Theme Generator

The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting it back, leading to a Reflected Cross-Site Scripting in the admin dashboard

THEME Child Theme Generator

CVE-2021-24982

MEDIUM CVSS 6.4 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2022-0440 - Catch Themes Demo Import

The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DISALLOW_UNFILTERED_HTML, DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS constants set to true)

THEME Catch Themes Demo Import

CVE-2022-0440

HIGH CVSS 7.2 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2021-24867 - Everest Admin Theme Lite

Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion

THEME Everest Admin Theme Lite

CVE-2021-24867

CRITICAL CVSS 9.8 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-24840 - Before 3 Theme

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

THEME Before 3

CVE-2021-24840

MEDIUM CVSS 5.3 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-39352 - Catch Themes Demo Import

The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution.

THEME Catch Themes Demo Import

CVE-2021-39352

HIGH CVSS 7.2 2021-10-21
Threat Entry Updated 2024-11-21

CVE-2021-24752 - Catch Themes Demo Import

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu WordPress plugin before…

THEME Catch Themes Demo Import

CVE-2021-24752

MEDIUM CVSS 5.7 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24719 - Enfold Enfold Theme

The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.

THEME Enfold Enfold

CVE-2021-24719

MEDIUM CVSS 6.1 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24499 - Before 2 Theme

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.

THEME Before 2

CVE-2021-24499

CRITICAL CVSS 9.8 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24501 - Before 2 Theme

The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects. This allowed a logged in user to modify or delete objects belonging to other users on the site.

THEME Before 2

CVE-2021-24501

HIGH CVSS 8.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24500 - Several Ajax Actions Available In The Workreap Theme

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

THEME Several Ajax Actions Available In The Workreap

CVE-2021-24500

HIGH CVSS 8.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24304 - Before 5 Theme

The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.

THEME Before 5

CVE-2021-24304

MEDIUM CVSS 6.1 2021-08-09
Threat Entry Updated 2024-11-21

CVE-2021-24472 - Before 3 Theme

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

THEME Before 3

CVE-2021-24472

CRITICAL CVSS 9.8 2021-08-02
Threat Entry Updated 2024-11-21

CVE-2021-24407 - Before 5 Theme

The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.

THEME Before 5

CVE-2021-24407

MEDIUM CVSS 6.1 2021-07-06
Scroll to top