Vulnerabilidades en aonetheme
9 resultadosAnálisis Vexday
O aonetheme possui 9 vulnerabilidades registradas, com 6 em nível crítico, mas nenhuma sob exploração ativa conhecida. A fraqueza dominante (CWE-639) aponta para problemas de autorização, sugerindo que o maior risco reside em falhas de controle de acesso. Não há registros de novas vulnerabilidades nos últimos 90 dias, indicando que o fornecedor não é alvo recente de descobertas, reduzindo a urgência de ação imediata, embora as críticas existentes permaneçam como exposição significativa.
CVE-2025-5947CRITICALService Finder Bookings <= 6.0 - Authentication Bypass via User Switch CookieEPSS 4.5%CVE-2025-23970CRITICALWordPress Service Finder Booking plugin <= 6.1 - Privilege Escalation VulnerabilityEPSS 0.7%CVE-2025-2470CRITICALService Finder Bookings <= 5.1 - Unauthenticated Privilege Escalation via 'nsl_registration_store_extra_input'EPSS 0.4%CVE-2025-5954CRITICALService Finder SMS System <= 2.0.0 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2025-5955HIGHService Finder SMS System <= 2.0.0 - Authentication BypassEPSS 0.4%CVE-2024-13442CRITICALService Finder Bookings <= 5.0 - Unauthenticated Privilege Escalation via Account TakeoverEPSS 0.4%CVE-2025-5948CRITICALService Finder Bookings <= 6.0 - Unauthenticated Privilege Escalation via claim_businessEPSS 0.4%CVE-2025-5949HIGHService Finder Bookings <= 6.0 - Authenticated (Subscriber+) Privilege Escalation via change_candidate_passwordEPSS 0.4%CVE-2025-6574HIGHService Finder Bookings < 6.1 - Authenticated (Subscriber+) Privilege Escalation via Account TakeoverEPSS 0.3%