Lucene search

K

Themegrill Security Vulnerabilities

cve
cve

CVE-2020-36333

themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

9.1CVSS

9.2AI Score

0.001EPSS

2021-05-05 04:15 AM
49
4
cve
cve

CVE-2020-36334

themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.

8.8CVSS

8.6AI Score

0.002EPSS

2021-05-05 04:15 AM
48
6
cve
cve

CVE-2024-0679

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and ac...

6.5CVSS

6.8AI Score

0.001EPSS

2024-01-20 06:15 AM
15
cve
cve

CVE-2024-1370

The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber access ...

5.3CVSS

5.9AI Score

0.0004EPSS

2024-03-13 04:15 PM
12
cve
cve

CVE-2024-1462

The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles and content when the site is in maintenance mode.

5.3CVSS

5.5AI Score

0.0004EPSS

2024-03-13 04:15 PM
12
cve
cve

CVE-2024-2500

The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authentciated attackers, with contributor-level access and above...

6.4CVSS

7.8AI Score

0.0004EPSS

2024-03-22 02:15 AM
36
cve
cve

CVE-2024-33540

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill ColorNews allows Stored XSS.This issue affects ColorNews: from n/a through 1.2.6.

6.5CVSS

6.6AI Score

0.0004EPSS

2024-04-29 06:15 AM
27
cve
cve

CVE-2024-34571

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.0.

6.5CVSS

6.6AI Score

0.0004EPSS

2024-05-08 10:15 AM
35
cve
cve

CVE-2024-37432

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Esteem allows Stored XSS.This issue affects Esteem: from n/a through 1.5.0.

7.1CVSS

6.9AI Score

0.0005EPSS

2024-07-22 09:15 AM
28
cve
cve

CVE-2024-39629

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.2.

5.9CVSS

5.8AI Score

0.0004EPSS

2024-08-01 11:15 PM
29