Vulnerabilidades em Aonetheme
11 resultadosAnálise Vexday
Aonetheme apresenta um pequeno volume de exposições (2 CVEs), ambas publicadas recentemente (últimos 90 dias), mas nenhuma está sob exploração ativa documentada no momento. A ausência de vulnerabilidades críticas reduz o risco imediato, porém a fraqueza dominante (CWE-266 - Permissões Incorretas) sugere problemas de controle de acesso que demandam revisão da implementação de segurança.
CVE-2025-5947CRITICALService Finder Bookings <= 6.0 - Authentication Bypass via User Switch CookieEPSS 4.5%CVE-2025-23970CRITICALWordPress Service Finder Booking plugin <= 6.1 - Privilege Escalation VulnerabilityEPSS 0.7%CVE-2025-2470CRITICALService Finder Bookings <= 5.1 - Unauthenticated Privilege Escalation via 'nsl_registration_store_extra_input'EPSS 0.4%CVE-2025-5955HIGHService Finder SMS System <= 2.0.0 - Authentication BypassEPSS 0.4%CVE-2025-5948CRITICALService Finder Bookings <= 6.0 - Unauthenticated Privilege Escalation via claim_businessEPSS 0.4%CVE-2024-13442CRITICALService Finder Bookings <= 5.0 - Unauthenticated Privilege Escalation via Account TakeoverEPSS 0.4%CVE-2025-5954CRITICALService Finder SMS System <= 2.0.0 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2026-28161HIGHWordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2026-28159MEDIUMWordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-5949HIGHService Finder Bookings <= 6.0 - Authenticated (Subscriber+) Privilege Escalation via change_candidate_passwordEPSS 0.4%CVE-2025-6574HIGHService Finder Bookings < 6.1 - Authenticated (Subscriber+) Privilege Escalation via Account TakeoverEPSS 0.3%