Skip to content
Noroxi

Themewinter records

22 published records for vendor themewinter.

All records

22 records
  • WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 28%

    themewinter · eventinMay 23, 2025

  • WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    themewinter · eventinMay 14, 2025

  • WordPress WPCafe plugin <= 2.2.22 - Broken Access Control vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    themewinter · wpcafeDec 9, 2024

  • CVE-2024-7149
    35Monitor

    Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion

    HighCVSS 8.8No exploitEPSS 1%

    themewinter · eventinSep 27, 2024

  • CVE-2025-1770
    35Monitor

    Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion

    HighCVSS 8.8No exploitEPSS 1%

    themewinter · eventinMar 20, 2025

  • WordPress Eventin plugin <= 4.0.20 - Local File Inclusion vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    themewinter · eventinFeb 25, 2025

  • CVE-2024-5431
    35Monitor

    WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcode

    HighCVSS 8.8No exploitEPSS 1%

    themewinter · wpcafeJun 25, 2024

  • CVE-2025-4796
    35Monitor

    Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

    HighCVSS 8.8Proof of conceptEPSS 1%

    themewinter · eventinAug 8, 2025

  • WordPress Eventin plugin <= 3.3.52 - Authenticated Notice Dismissal Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    themewinter · eventinDec 9, 2024

  • WordPress Eventin plugin <= 4.0.7 - Contributor+ Limited Local File Inclusion vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    themewinter · eventinDec 31, 2024

  • WordPress WPCafe plugin <= 2.2.27 - Local File Inclusion vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    themewinter · wpcafeJul 9, 2024

  • WordPress WPCafe plugin <= 2.2.28 - Local File Inclusion vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    themewinter · wpcafeAug 13, 2024

  • WordPress Eventin plugin <= 4.0.25 - Local File Inclusion Vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    themewinter · eventinApr 16, 2025

  • CVE-2025-3419
    30Monitor

    Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read

    HighCVSS 7.5Proof of conceptEPSS 1%

    themewinter · eventinMay 8, 2025

  • WordPress Eventin plugin <= 4.0.28 - Cross Site Scripting (XSS) Vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    themewinter · eventinJun 27, 2025

  • CVE-2024-1122
    21Monitor

    Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin <= 3.3.50 - Missing Authorization to Unauthenticated Events Export

    MediumCVSS 5.3No exploitEPSS 0%

    themewinter · eventinFeb 9, 2024

  • CVE-2024-1855
    21Monitor

    WPCafe <= 2.2.23 - Unauthenticated Blind Server-Side Request Forgery

    MediumCVSS 5.3No exploitEPSS 0%

    themewinter · wpcafeMay 22, 2024

  • CVE-2025-1766
    21Monitor

    Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update

    MediumCVSS 5.3No exploitEPSS 0%

    themewinter · eventinMar 20, 2025

  • CVE-2024-5427
    21Monitor

    WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    themewinter · wpcafeMay 31, 2024

  • WordPress Eventin plugin <= 3.3.57 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    themewinter · eventinJul 21, 2024

  • WordPress Eventin plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 4.8No exploitEPSS 0%

    themewinter · eventinAug 1, 2024

  • CVE-2024-6033
    17Monitor

    Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import

    MediumCVSS 4.3No exploitEPSS 0%

    themewinter · eventinJul 17, 2024