ThemeAtelier kayıtları
themeatelier üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %25
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-862 Missing Authorization3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-285 Improper Authorization1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-32519İstismar yok | WordPress IDonate plugin <= 2.1.18 - Local File Inclusion vulnerabilitythemeatelier · idonate · CWE-98 | Kritik9,8 | — | %0,9 | 11 Nis 2025 |
35İzleyin | CVE-2025-4519İstismar yok | IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Functionthemeatelier · idonate · CWE-285 | Yüksek8,8 | — | %0,3 | 7 Kas 2025 |
34İzleyin | CVE-2024-3594İstismar yok | IDonate <= 1.9.0 - Admin+ Stored XSSthemeatelier · idonate · CWE-79 | Yüksek8,7 | — | %0,5 | 23 May 2024 |
26İzleyin | CVE-2025-4523İstismar yok | IDonate 2.0.0 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Functionthemeatelier · idonate · CWE-200 | Orta6,5 | — | %0,3 | 1 Ağu 2025 |
26İzleyin | CVE-2025-4522İstismar yok | IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Functionthemeatelier · idonate · CWE-862 | Orta6,5 | — | %0,3 | 7 Kas 2025 |
21İzleyin | CVE-2025-12877İstismar yok | IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletionthemeatelier · idonate · CWE-862 | Orta5,3 | — | %0,3 | 22 Kas 2025 |
21İzleyin | CVE-2025-67583İstismar yok | WordPress IDonate plugin <= 2.1.15 - Broken Access Control vulnerabilitythemeatelier · idonate · CWE-862 | Orta5,3 | — | %0,2 | 9 Ara 2025 |
21İzleyin | CVE-2025-11154İstismar yok | IDonate < 2.1.13 - Unauthenticated User Deletionthemeatelier · idonate · CWE-352 | Orta5,4 | — | %0,1 | 27 Eki 2025 |
- CVE-2025-3251939İzleyin
WordPress IDonate plugin <= 2.1.18 - Local File Inclusion vulnerability
KritikCVSS 9,8İstismar yokEPSS %1themeatelier · idonate11 Nis 2025
- CVE-2025-451935İzleyin
IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_password Function
YüksekCVSS 8,8İstismar yokEPSS %0themeatelier · idonate7 Kas 2025
- CVE-2024-359434İzleyin
IDonate <= 1.9.0 - Admin+ Stored XSS
YüksekCVSS 8,7İstismar yokEPSS %1themeatelier · idonate23 May 2024
- CVE-2025-452326İzleyin
IDonate 2.0.0 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via admin_donor_profile_view Function
OrtaCVSS 6,5İstismar yokEPSS %0themeatelier · idonate1 Ağu 2025
- CVE-2025-452226İzleyin
IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function
OrtaCVSS 6,5İstismar yokEPSS %0themeatelier · idonate7 Kas 2025
- CVE-2025-1287721İzleyin
IDonate – Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
OrtaCVSS 5,3İstismar yokEPSS %0themeatelier · idonate22 Kas 2025
- CVE-2025-6758321İzleyin
WordPress IDonate plugin <= 2.1.15 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0themeatelier · idonate9 Ara 2025
- CVE-2025-1115421İzleyin
IDonate < 2.1.13 - Unauthenticated User Deletion
OrtaCVSS 5,4İstismar yokEPSS %0themeatelier · idonate27 Eki 2025