Vulnerabilities in themeisle

111 results
Vexday analysis

Com 65 CVEs catalogadas, o portfólio de plugins e temas da Themeisle apresenta taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem nenhum registro confirmado de exploração em ambiente real. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em componentes WordPress que lidam com entrada de usuário sem sanitização adequada. A CVE mais relevante no momento é CVE-2024-3105, com score EPSS de 0,0278, indicando probabilidade ainda baixa de exploração massiva a curto prazo, embora a existência de uma prova de conceito pública exija atenção redobrada por parte de equipes de segurança. As 4 CVEs surgidas nos últimos 90 dias e as 3 classificadas como críticas reforçam a necessidade de monitoramento contínuo e atualização prioritária dos produtos afetados.

CVE-2024-10705MEDIUMMultiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrlEPSS 0.3%CVE-2024-2841MEDIUMOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-56050MEDIUMWordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-35728MEDIUMWordPress Product Addons & Fields for WooCommerce plugin <= 32.0.20 - Content Injection vulnerabilityEPSS 0.3%CVE-2024-7424MEDIUMMultiple Page Generator Plugin – MPG <= 4.0.1 - Missing AuthorizationEPSS 0.3%CVE-2024-7778MEDIUMOrbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadEPSS 0.3%CVE-2025-9322HIGHStripe Payment Forms <= 8.3.1 - Unauthenticated SQL InjectionEPSS 0.3%CVE-2023-7019MEDIUMLightStart – Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 - Missing AuthorizationEPSS 0.3%CVE-2026-2892HIGHOtter Blocks <= 3.1.4 - Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged CookieEPSS 0.3%CVE-2024-3344MEDIUMOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site ScriptingEPSS 0.3%CVE-2023-6801MEDIUMRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-9562MEDIUMRedirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date ShortcodeEPSS 0.3%CVE-2026-25366CRITICALWordPress Woody ad snippets plugin <= 2.7.1 - Remote Code Execution (RCE) vulnerabilityEPSS 0.3%CVE-2025-13794MEDIUMAuto Featured Image <= 4.2.1 - Missing Authorization to Authenticated (Contributor+) Post Thumbnail ModificationEPSS 0.3%CVE-2026-4945MEDIUMOtter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification BypassEPSS 0.3%CVE-2025-12483MEDIUMVisualizer: Tables and Charts Manager for WordPress <= 3.11.12 - Authenticated (Contributor+) SQL InjectionEPSS 0.3%CVE-2026-8976MEDIUMRSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-ActionsEPSS 0.3%CVE-2026-85198MEDIUMMPG <= 4.2.1 - Unauthenticated SQL Injection via URL PathEPSS 0.3%CVE-2023-6798MEDIUMRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing AuthorizationEPSS 0.3%CVE-2025-22659MEDIUMWordPress Orbit Fox by ThemeIsle plugin <= 2.10.44 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%