Vulnerabilities in ThemeIsle

108 results
Vexday analysis

ThemeIsle apresenta footprint mínimo de vulnerabilidades com apenas 1 CVE catalogado na base, sem registros de exploração ativa ou classificação crítica. A vulnerabilidade identificada refere-se a exposição de informações (CWE-200), sendo anterior aos últimos 90 dias, indicando risco baixo e estável no curto prazo.

CVE-2026-65526HIGHWordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerabilityEPSS 0.3%CVE-2022-47143MEDIUMWordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2023-7073MEDIUMAuto Featured Image (Auto Post Thumbnail) <= 4.1.7 - Authenticated (Author+) Server-Side Request ForgeryEPSS 0.3%CVE-2025-11467MEDIUMRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request ForgeryEPSS 0.3%CVE-2026-42749HIGHWordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2026-8689MEDIUMVisualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Chart Creation and Modification via renderChartPages() and uploadData() FunctionsEPSS 0.2%CVE-2026-23970HIGHWordPress Redirection for Contact Form 7 plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2024-1162MEDIUMOrbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request ForgeryEPSS 0.2%CVE-2025-12045MEDIUMOrbit Fox Companion <= 3.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post TaxonomyEPSS 0.2%CVE-2024-31301MEDIUMWordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2025-66069MEDIUMWordPress PPOM for WooCommerce plugin <= 33.0.16 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-65537MEDIUMWordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-1319MEDIUMRobin Image Optimizer <= 2.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Alternative Text FieldEPSS 0.2%CVE-2025-58593MEDIUMWordPress Orbit Fox by ThemeIsle Plugin <= 3.0.0 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.2%CVE-2026-13252MEDIUMRSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' AttributeEPSS 0.2%CVE-2024-37467MEDIUMWordPress Hestia theme <= 3.1.2 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2026-15653MEDIUMVisualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' ParameterEPSS 0.2%CVE-2026-56050MEDIUMWordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2024-52420MEDIUMWordPress Disable Admin Notices individually plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2026-1755MEDIUMMenu Icons by ThemeIsle <= 0.13.20 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.2%