Vulnerabilidades en Themeum
126 resultadosAnálisis Vexday
Themeum apresenta 48 vulnerabilidades registradas, com 11 publicadas nos últimos 90 dias, indicando cadência moderada de descobertas. Nenhuma vulnerabilidade está sob ataque ativo no momento, embora 4 sejam críticas; a fraqueza predominante é injeção de conteúdo (CWE-79), típica de aplicações web. O risco atual é gerenciável, mas a presença de críticas e o padrão recente de descobertas justificam monitoramento contínuo.
CVE-2026-89333MEDIUMTutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' ParameterEPSS 0.5%CVE-2026-8096MEDIUMKirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via 'kirki_wp_admin_get_apis' ActionEPSS 0.5%CVE-2024-3553MEDIUMTutor LMS <= 2.6.2 - Missing Authorization to Unauthenticated Limited Options UpdateEPSS 0.5%CVE-2026-88944MEDIUMTutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' ParameterEPSS 0.5%CVE-2023-25799HIGHWordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilitiesEPSS 0.5%CVE-2022-40963MEDIUMWordPress WP Page Builder plugin <= 1.2.6 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilitiesEPSS 0.4%CVE-2024-43282HIGHWordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerabilityEPSS 0.4%CVE-2024-1502MEDIUMTutor LMS – eLearning and online course solution <= 2.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post DeletionEPSS 0.4%CVE-2024-4279MEDIUMTutor LMS – eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course DeletionEPSS 0.4%CVE-2025-1508MEDIUMWP Crowdfunding <= 2.1.14 - Missing Authorization to Authenticated (Subscriber+) Post Content DownloadEPSS 0.4%CVE-2024-1798MEDIUMTutor LMS – Migration Tool <= 2.2.0 - Missing Authorization in tutor_lp_export_xmlEPSS 0.4%CVE-2026-5502MEDIUMTutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_orderEPSS 0.4%CVE-2024-43142MEDIUMWordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-57726CRITICALWordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerabilityEPSS 0.4%CVE-2023-49829MEDIUMWordPress Tutor LMS Plugin <= 2.2.4 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2026-57727HIGHWordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-3358MEDIUMTutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course EnrollmentEPSS 0.4%CVE-2024-3994MEDIUMTutor LMS – eLearning and online course solution <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' ShortcodeEPSS 0.4%CVE-2026-92465HIGHWordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerabilityEPSS 0.4%CVE-2026-89081MEDIUMTutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' ParametersEPSS 0.4%