Vulnerabilidades en themeum

111 resultados
Análisis Vexday

Com 52 CVEs catalogadas e nenhuma confirmada em exploração ativa no catálogo KEV da CISA, o vendor Themeum apresenta taxa de exploração abaixo da média geral do catálogo. No entanto, o cenário exige atenção: a CVE mais perigosa identificada, CVE-2024-10400, registra EPSS de 0,8259 — indicando alta probabilidade estimada de exploração —, e o tipo de falha predominante é CWE-862 (ausência de verificação de autorização), uma classe de vulnerabilidade que facilita acesso não autorizado a funcionalidades protegidas. O surgimento de 10 novas CVEs nos últimos 90 dias, combinado com a existência de prova de conceito pública para ao menos uma delas, sugere uma superfície de ataque em expansão que merece monitoramento contínuo e priorização de correções, especialmente em ambientes que dependem de plugins ou temas deste vendor.

CVE-2024-10400HIGHTutor LMS <= 2.7.6 - Unauthenticated SQL Injection via rating_filterEPSS 82.5%CVE-2024-1751HIGHTutor LMS – eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL InjectionEPSS 3.1%CVE-2026-8206CRITICALKirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'EPSS 1.3%CVE-2024-4352HIGHTutor LMS Pro <= 2.7.0 - Missing Authorization to SQL InjectionEPSS 1.2%CVE-2024-4351HIGHTutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege EscalationEPSS 1.0%CVE-2024-54282HIGHWordPress WP Mega Menu plugin <= 1.4.2 - PHP Object Injection vulnerabilityEPSS 0.8%CVE-2021-24242Tutor LMS < 1.8.8 - Authenticated Local File InclusionEPSS 0.8%CVE-2026-15601MEDIUMKirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)EPSS 0.8%CVE-2026-15457MEDIUMKirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' ParameterEPSS 0.8%CVE-2023-25700HIGHWordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL InjectionEPSS 0.8%CVE-2023-25800HIGHWordPress Tutor LMS Plugin <= 2.2.0 is vulnerable to SQL InjectionEPSS 0.7%CVE-2023-25990HIGHWordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL InjectionEPSS 0.7%CVE-2026-0953CRITICALTutor LMS Pro <= 3.9.5 - Authentication Bypass via Social LoginEPSS 0.7%CVE-2023-41870MEDIUMWordPress WP Crowdfunding plugin <= 2.1.5 - Broken Access Control vulnerabilityEPSS 0.6%CVE-2024-37266MEDIUMWordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerabilityEPSS 0.6%CVE-2026-3360HIGHTutor LMS <= 3.9.7 - Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' ParameterEPSS 0.6%CVE-2024-43955CRITICALWordPress Droip plugin <= 1.1.1 - Unauthenticated Arbitrary File Download/Deletion vulnerabilityEPSS 0.6%CVE-2024-37256HIGHWordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerabilityEPSS 0.6%CVE-2026-8073HIGHKirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIPEPSS 0.6%CVE-2024-10393MEDIUMTutor LMS <= 2.7.6 - User Registration Setting Bypass to Unauthorized User RegistrationEPSS 0.6%