Vulnerabilidades en Themeisle
111 resultadosAnálisis Vexday
Themeisle acumula 34 vulnerabilidades catalogadas, com 4 críticas e tendência crescente de 10 descobertas nos últimos 90 dias; a fraqueza dominante é injeção cross-site (CWE-79), padrão em componentes web. Não há exploração ativa documentada no momento, mas o ritmo recente de divulgações e a natureza das falhas exigem monitoramento contínuo de atualizações.
CVE-2023-6877MEDIUMRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error MessageEPSS 0.3%CVE-2025-0311MEDIUMOrbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table WidgetEPSS 0.3%CVE-2026-13252MEDIUMRSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' AttributeEPSS 0.3%CVE-2024-35682MEDIUMWordPress Otter Blocks PRO plugin <= 2.6.11 - Authenticated Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2024-3343MEDIUMOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block AttributesEPSS 0.3%CVE-2024-10705MEDIUMMultiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrlEPSS 0.3%CVE-2023-6805MEDIUMRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF)EPSS 0.3%CVE-2024-2841MEDIUMOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-56050MEDIUMWordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-15653MEDIUMVisualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' ParameterEPSS 0.3%CVE-2024-35728MEDIUMWordPress Product Addons & Fields for WooCommerce plugin <= 32.0.20 - Content Injection vulnerabilityEPSS 0.3%CVE-2024-7424MEDIUMMultiple Page Generator Plugin – MPG <= 4.0.1 - Missing AuthorizationEPSS 0.3%CVE-2024-7778MEDIUMOrbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadEPSS 0.3%CVE-2025-9322HIGHStripe Payment Forms <= 8.3.1 - Unauthenticated SQL InjectionEPSS 0.3%CVE-2023-7019MEDIUMLightStart – Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 - Missing AuthorizationEPSS 0.3%CVE-2024-3344MEDIUMOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site ScriptingEPSS 0.3%CVE-2023-6801MEDIUMRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-9562MEDIUMRedirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date ShortcodeEPSS 0.3%CVE-2026-25366CRITICALWordPress Woody ad snippets plugin <= 2.7.1 - Remote Code Execution (RCE) vulnerabilityEPSS 0.3%CVE-2025-13794MEDIUMAuto Featured Image <= 4.2.1 - Missing Authorization to Authenticated (Contributor+) Post Thumbnail ModificationEPSS 0.3%