Vulnerabilidades em themeum

125 resultados
Análise Vexday

Com 52 CVEs catalogadas e nenhuma confirmada em exploração ativa no catálogo KEV da CISA, o vendor Themeum apresenta taxa de exploração abaixo da média geral do catálogo. No entanto, o cenário exige atenção: a CVE mais perigosa identificada, CVE-2024-10400, registra EPSS de 0,8259 — indicando alta probabilidade estimada de exploração —, e o tipo de falha predominante é CWE-862 (ausência de verificação de autorização), uma classe de vulnerabilidade que facilita acesso não autorizado a funcionalidades protegidas. O surgimento de 10 novas CVEs nos últimos 90 dias, combinado com a existência de prova de conceito pública para ao menos uma delas, sugere uma superfície de ataque em expansão que merece monitoramento contínuo e priorização de correções, especialmente em ambientes que dependem de plugins ou temas deste vendor.

CVE-2024-1502MEDIUMTutor LMS – eLearning and online course solution <= 2.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post DeletionEPSS 0.4%CVE-2024-4279MEDIUMTutor LMS – eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course DeletionEPSS 0.4%CVE-2025-1508MEDIUMWP Crowdfunding <= 2.1.14 - Missing Authorization to Authenticated (Subscriber+) Post Content DownloadEPSS 0.4%CVE-2024-1798MEDIUMTutor LMS – Migration Tool <= 2.2.0 - Missing Authorization in tutor_lp_export_xmlEPSS 0.4%CVE-2026-8096MEDIUMKirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via 'kirki_wp_admin_get_apis' ActionEPSS 0.4%CVE-2024-43142MEDIUMWordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-57726CRITICALWordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerabilityEPSS 0.4%CVE-2023-49829MEDIUMWordPress Tutor LMS Plugin <= 2.2.4 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2026-57727HIGHWordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-3994MEDIUMTutor LMS – eLearning and online course solution <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' ShortcodeEPSS 0.4%CVE-2024-1133MEDIUMTutor LMS <= 2.6.0 - Missing AuthorizationEPSS 0.4%CVE-2026-3358MEDIUMTutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course EnrollmentEPSS 0.4%CVE-2024-10117MEDIUMWP Crowdfunding <= 2.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpcf_donate ShortcodeEPSS 0.4%CVE-2023-47532MEDIUMWordPress WP Crowdfunding Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2026-22330HIGHWordPress Right Way theme <= 4.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2024-13228MEDIUMQubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_contentEPSS 0.4%CVE-2026-3371MEDIUMTutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content ModificationEPSS 0.4%CVE-2025-6184HIGHTutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL InjectionEPSS 0.4%CVE-2026-1375HIGHTutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and DeletionEPSS 0.4%CVE-2024-43937MEDIUMWordPress WP Crowdfunding plugin <= 2.1.10 - Settings Change vulnerabilityEPSS 0.4%