Lucene search

K

ThemeNectar Security Vulnerabilities

cve
cve

CVE-2024-3812

The Salient Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.7 via the 'nectar_icon' shortcode 'icon_linea' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute...

7.5CVSS

7.5AI Score

0.001EPSS

2024-05-18 06:15 AM
37
cve
cve

CVE-2024-3810

The Salient Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.3 via the 'icon' shortcode 'image' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute...

8.8CVSS

7.5AI Score

0.001EPSS

2024-05-18 06:15 AM
29
cve
cve

CVE-2024-3811

The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortcode in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

6.4CVSS

5.7AI Score

0.0004EPSS

2024-05-18 06:15 AM
35
cve
cve

CVE-2023-48748

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Reflected XSS.This issue affects Salient Core: from n/a through...

7.1CVSS

6.5AI Score

0.0005EPSS

2023-11-30 05:15 PM
44
cve
cve

CVE-2023-48749

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Stored XSS.This issue affects Salient Core: from n/a through...

6.5CVSS

5.8AI Score

0.0004EPSS

2023-11-30 05:15 PM
45