Vulnerabilidades en designthemes
44 resultadosAnálisis Vexday
A DesignThemes acumula 39 vulnerabilidades catalogadas, com 4 delas críticas (CVSS alto), mas nenhuma sob exploração ativa confirmada até o momento. A fraqueza predominante é CWE-502 (deserialização não segura), um padrão estrutural que sugere problemas arquiteturais; apenas 2 novas vulnerabilidades surgiram nos últimos 90 dias, indicando risco moderado e não imediato.
CVE-2024-13787CRITICALVEDA - MultiPurpose WordPress Theme <= 4.2 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.7%CVE-2025-67619HIGHWordPress Kids Heaven theme <= 3.2 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-31634HIGHWordPress Insurance theme <= 3.5 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2025-32283HIGHWordPress Solar Energy theme <= 3.5 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2025-31924HIGHWordPress Crafts & Arts theme <= 2.5 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2025-32293HIGHWordPress Finance Consultant theme <= 2.8 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2025-32284HIGHWordPress Pet World theme <= 2.8 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2024-13471HIGHDesignThemes Core Features <= 4.7 - Missing Authorization to Unauthenticated Arbitrary File Read via dt_process_imported_fileEPSS 0.5%CVE-2025-60234HIGHWordPress Single Property theme <= 2.8 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-60228HIGHWordPress Knowledge Base theme <= 2.9 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-60212HIGHWordPress VEDA Theme <= 4.2 - PHP Object Injection VulnerabilityEPSS 0.5%CVE-2025-60215HIGHWordPress Kriya theme <= 3.4 - PHP Object Injection VulnerabilityEPSS 0.5%CVE-2026-27390HIGHWordPress WeDesignTech Ultimate Booking Addon plugin <= 1.0.1 - Account Takeover vulnerabilityEPSS 0.5%CVE-2025-68899HIGHWordPress Vivagh theme <= 2.4 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-31422HIGHWordPress Visual Art | Gallery WordPress Theme <= 2.4 - PHP Object Injection VulnerabilityEPSS 0.5%CVE-2026-27389CRITICALWordPress WeDesignTech Ultimate Booking Addon plugin <= 1.0.1 - Account Takeover vulnerabilityEPSS 0.4%CVE-2025-69002HIGHWordPress OneLife theme <= 3.9 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-27388HIGHWordPress DesignThemes Booking Manager plugin <= 2.0 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-13542CRITICALDesignThemes LMS <= 1.0.4 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2026-22473HIGHWordPress Dental Clinic theme <= 3.7 - PHP Object Injection vulnerabilityEPSS 0.4%