Vulnerabilities in Themeum

111 results
Vexday analysis

Themeum apresenta 48 vulnerabilidades registradas, com 11 publicadas nos últimos 90 dias, indicando cadência moderada de descobertas. Nenhuma vulnerabilidade está sob ataque ativo no momento, embora 4 sejam críticas; a fraqueza predominante é injeção de conteúdo (CWE-79), típica de aplicações web. O risco atual é gerenciável, mas a presença de críticas e o padrão recente de descobertas justificam monitoramento contínuo.

CVE-2024-3994MEDIUMTutor LMS – eLearning and online course solution <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' ShortcodeEPSS 0.4%CVE-2024-1133MEDIUMTutor LMS <= 2.6.0 - Missing AuthorizationEPSS 0.4%CVE-2026-57724CRITICALWordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-3358MEDIUMTutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course EnrollmentEPSS 0.4%CVE-2024-10117MEDIUMWP Crowdfunding <= 2.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpcf_donate ShortcodeEPSS 0.4%CVE-2023-47532MEDIUMWordPress WP Crowdfunding Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2026-22330HIGHWordPress Right Way theme <= 4.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-3371MEDIUMTutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content ModificationEPSS 0.4%CVE-2024-43937MEDIUMWordPress WP Crowdfunding plugin <= 2.1.10 - Settings Change vulnerabilityEPSS 0.4%CVE-2024-5784HIGHTutor LMS Pro <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Insecure Direct Object ReferenceEPSS 0.4%CVE-2024-37947MEDIUMWordPress Tutor LMS plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2024-13228MEDIUMQubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_contentEPSS 0.4%CVE-2025-6184HIGHTutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL InjectionEPSS 0.4%CVE-2026-1375HIGHTutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and DeletionEPSS 0.3%CVE-2024-5438MEDIUMTutor LMS – eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt DeletionEPSS 0.3%CVE-2026-13464MEDIUMKirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' ParameterEPSS 0.3%CVE-2026-25406HIGHWordPress Tutor LMS Pro plugin <= 3.9.4 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2024-5576MEDIUMTutor LMS Elementor Addons <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Course Carousel WidgetEPSS 0.3%CVE-2026-15022MEDIUMTutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer ArrayEPSS 0.3%CVE-2024-29913MEDIUMWordPress Tutor LMS Elementor Addons plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%