Vulnerabilities in themeisle

111 results
Vexday analysis

Com 65 CVEs catalogadas, o portfólio de plugins e temas da Themeisle apresenta taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem nenhum registro confirmado de exploração em ambiente real. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em componentes WordPress que lidam com entrada de usuário sem sanitização adequada. A CVE mais relevante no momento é CVE-2024-3105, com score EPSS de 0,0278, indicando probabilidade ainda baixa de exploração massiva a curto prazo, embora a existência de uma prova de conceito pública exija atenção redobrada por parte de equipes de segurança. As 4 CVEs surgidas nos últimos 90 dias e as 3 classificadas como críticas reforçam a necessidade de monitoramento contínuo e atualização prioritária dos produtos afetados.

CVE-2020-36759MEDIUMWoody code snippets <= 2.3.9 - Cross-Site Request Forgery BypassEPSS 0.4%CVE-2023-4887MEDIUMGoogle Maps Plugin by Intergeo <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.4%CVE-2025-8289HIGHRedirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection via PHAR DeserializationEPSS 0.4%CVE-2026-42378MEDIUMWordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerabilityEPSS 0.4%CVE-2024-2484MEDIUMOrbit Fox by ThemeIsle <= 2.10.34 - Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid WidgetsEPSS 0.4%CVE-2025-55715HIGHWordPress Otter - Gutenberg Block Plugin <= 3.1.0 - Sensitive Data Exposure VulnerabilityEPSS 0.4%CVE-2024-4635MEDIUMMenu Icons by ThemeIsle <= 0.13.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG UploadEPSS 0.4%CVE-2023-2608LOWMultiple Page Generator Plugin <= 3.3.17 - Cross-Site Request Forgery to SQL InjectionEPSS 0.4%CVE-2024-2226MEDIUMOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-65526HIGHWordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerabilityEPSS 0.4%CVE-2024-10367MEDIUMOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadEPSS 0.4%CVE-2025-58789HIGHWordPress WP Full Stripe Free Plugin <= 8.2.5 - SQL Injection VulnerabilityEPSS 0.4%CVE-2025-24666MEDIUMWordPress Hyve Lite plugin <= 1.2.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2025-24668MEDIUMWordPress PPOM for WooCommerce plugin <= 33.0.8 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2026-13252MEDIUMRSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' AttributeEPSS 0.3%CVE-2023-6877MEDIUMRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error MessageEPSS 0.3%CVE-2025-0311MEDIUMOrbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table WidgetEPSS 0.3%CVE-2024-35682MEDIUMWordPress Otter Blocks PRO plugin <= 2.6.11 - Authenticated Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2024-3343MEDIUMOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block AttributesEPSS 0.3%CVE-2023-6805MEDIUMRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF)EPSS 0.3%