Vulnerabilities in Themeum

126 results
Vexday analysis

Themeum apresenta 48 vulnerabilidades registradas, com 11 publicadas nos últimos 90 dias, indicando cadência moderada de descobertas. Nenhuma vulnerabilidade está sob ataque ativo no momento, embora 4 sejam críticas; a fraqueza predominante é injeção de conteúdo (CWE-79), típica de aplicações web. O risco atual é gerenciável, mas a presença de críticas e o padrão recente de descobertas justificam monitoramento contínuo.

CVE-2024-1133MEDIUMTutor LMS <= 2.6.0 - Missing AuthorizationEPSS 0.4%CVE-2024-10117MEDIUMWP Crowdfunding <= 2.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpcf_donate ShortcodeEPSS 0.4%CVE-2026-1375HIGHTutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and DeletionEPSS 0.4%CVE-2023-47532MEDIUMWordPress WP Crowdfunding Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2026-22330HIGHWordPress Right Way theme <= 4.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2024-13228MEDIUMQubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_contentEPSS 0.4%CVE-2025-6184HIGHTutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL InjectionEPSS 0.4%CVE-2024-43937MEDIUMWordPress WP Crowdfunding plugin <= 2.1.10 - Settings Change vulnerabilityEPSS 0.4%CVE-2026-13443MEDIUMTutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment TitleEPSS 0.4%CVE-2024-5784HIGHTutor LMS Pro <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Insecure Direct Object ReferenceEPSS 0.4%CVE-2026-1372MEDIUMTutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin ActivationEPSS 0.4%CVE-2024-37947MEDIUMWordPress Tutor LMS plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2024-5438MEDIUMTutor LMS – eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt DeletionEPSS 0.3%CVE-2026-25406HIGHWordPress Tutor LMS Pro plugin <= 3.9.4 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2024-5576MEDIUMTutor LMS Elementor Addons <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Course Carousel WidgetEPSS 0.3%CVE-2026-3371MEDIUMTutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content ModificationEPSS 0.3%CVE-2024-29913MEDIUMWordPress Tutor LMS Elementor Addons plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2026-57694MEDIUMWordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2025-47555LOWWordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-57680MEDIUMWordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%