themeisle records
61 published records for vendor themeisle.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 27.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')27
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-862 Missing Authorization5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
The weakness classes this vendor ships most often: where to look.
CWEAll records
61 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2019-16932Proof of concept | A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.themeisle · visualizer · CWE-918 | Critical10.0 | — | 39.1% | Sep 30, 2019 |
40Plan | CVE-2023-2288No exploit | Otter - Gutenberg Blocks < 2.2.6 - Author+ PHAR Deserializationthemeisle · otter · CWE-502 | High8.8 | — | 18.0% | May 30, 2023 |
39Monitor | CVE-2024-3962No exploit | Product Addons & Fields for WooCommerce <= 32.0.18 - Unauthenticated Arbitrary File Upload via ppom_upload_filethemeisle · product addons \& fields for woocommerce · CWE-434 | Critical9.8 | — | 1.4% | Apr 26, 2024 |
39Monitor | CVE-2023-33927No exploit | WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.19 is vulnerable to SQL Injectionthemeisle · multiple page generator · CWE-89 | Critical9.8 | — | 0.7% | Oct 31, 2023 |
36Monitor | CVE-2022-2444No exploit | Visualizer: Tables and Charts Manager for WordPress <= 3.7.9 - Authenticated (Contributor+) PHAR Deserializationthemeisle · visualizer · CWE-502 | High8.8 | — | 2.3% | Jul 18, 2022 |
35Monitor | CVE-2024-1317No exploit | RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injectionthemeisle · rss aggregator by feedzy · CWE-89 | High8.8 | — | 0.7% | Feb 28, 2024 |
35Monitor | CVE-2024-47325No exploit | WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.7 - SQL Injection vulnerabilitythemeisle · multiple page generator · CWE-89 | High8.8 | — | 0.5% | Oct 20, 2024 |
35Monitor | CVE-2024-35736No exploit | WordPress Visualizer plugin <= 3.11.1 - SQL Injection vulnerabilitythemeisle · visualizer · CWE-89 | High8.8 | — | 0.4% | Jun 8, 2024 |
35Monitor | CVE-2024-30235No exploit | WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Broken Access Control vulnerabilitythemeisle · multiple page generator · CWE-862 | High8.8 | — | 0.4% | Mar 26, 2024 |
35Monitor | CVE-2022-47143No exploit | WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF)themeisle · multiple page generator · CWE-352 | High8.8 | — | 0.3% | Mar 14, 2023 |
35Monitor | CVE-2024-31301No exploit | WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) vulnerabilitythemeisle · multiple page generator · CWE-352 | High8.8 | — | 0.2% | Apr 12, 2024 |
32Monitor | CVE-2024-10705No exploit | Multiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrlthemeisle · multiple page generator · CWE-918 | High8.1 | — | 0.3% | Jan 26, 2025 |
30Monitor | CVE-2023-47529Proof of concept | WordPress Cloud Templates & Patterns collection Plugin <= 1.2.2 is vulnerable to Sensitive Data Exposurethemeisle · cloud templates \& patterns collection · CWE-200 | High7.5 | — | 1.0% | Nov 23, 2023 |
30Monitor | CVE-2024-11219No exploit | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image Viewthemeisle · otter blocks · CWE-22 | High7.5 | — | 0.5% | Nov 27, 2024 |
28Monitor | CVE-2023-2607No exploit | Multiple Page Generator Plugin <= 3.3.17 - Authenticated (Administrator+) SQL Injectionthemeisle · multiple page generator · CWE-89 | High7.2 | — | 0.8% | Jun 9, 2023 |
28Monitor | CVE-2024-27951No exploit | WordPress Multiple Page Generator Plugin <= 3.4.0 - Auth. Remote Code Execution (RCE) vulnerabilitythemeisle · multiple page generator · CWE-434 | High7.2 | — | 0.6% | Apr 3, 2024 |
26Monitor | CVE-2021-24158No exploit | Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Privilege Escalationthemeisle · orbit fox · CWE-269 | Medium6.5 | — | 0.9% | Apr 5, 2021 |
26Monitor | CVE-2022-1576No exploit | WP Maintenance Mode & Coming Soon < 2.4.5 - Subscribed Users Deletion via CSRFthemeisle · wp maintenance mode \& coming soon · CWE-352 | Medium6.5 | — | 0.5% | Jul 11, 2022 |
26Monitor | CVE-2024-1318No exploit | RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publicationthemeisle · rss aggregator by feedzy · CWE-862 | Medium6.5 | — | 0.5% | Feb 28, 2024 |
25Monitor | CVE-2019-16931Proof of concept | A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript wthemeisle · visualizer · CWE-79 | Medium6.1 | — | 3.3% | Oct 3, 2019 |
25Monitor | CVE-2023-6805No exploit | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Fothemeisle · rss aggregator by feedzy · CWE-918 | Medium6.4 | — | 0.3% | Apr 17, 2024 |
24Monitor | CVE-2023-2256Proof of concept | Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scriptingthemeisle · product addons \& fields for woocommerce · CWE-79 | Medium6.1 | — | 1.0% | May 30, 2023 |
24Monitor | CVE-2024-1691No exploit | Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Uploadthemeisle · otter blocks · CWE-79 | Medium6.1 | — | 0.5% | Mar 13, 2024 |
24Monitor | CVE-2024-27958No exploit | WordPress Visualizer plugin <= 3.10.5 - Reflected Cross Site Scripting (XSS) vulnerabilitythemeisle · visualizer · CWE-79 | Medium6.1 | — | 0.4% | Mar 17, 2024 |
24Monitor | CVE-2024-2729No exploit | Otter Blocks < 2.6.6 - Contributor+ Stored XSSthemeisle · otter blocks · CWE-79 | Medium6.1 | — | 0.4% | Apr 18, 2024 |
- CVE-2019-1693252Plan
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
CriticalCVSS 10.0Proof of conceptEPSS 39%themeisle · visualizerSep 30, 2019
- CVE-2023-228840Plan
Otter - Gutenberg Blocks < 2.2.6 - Author+ PHAR Deserialization
HighCVSS 8.8No exploitEPSS 18%themeisle · otterMay 30, 2023
- CVE-2024-396239Monitor
Product Addons & Fields for WooCommerce <= 32.0.18 - Unauthenticated Arbitrary File Upload via ppom_upload_file
CriticalCVSS 9.8No exploitEPSS 1%themeisle · product addons \& fields for woocommerceApr 26, 2024
- CVE-2023-3392739Monitor
WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.19 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%themeisle · multiple page generatorOct 31, 2023
- CVE-2022-244436Monitor
Visualizer: Tables and Charts Manager for WordPress <= 3.7.9 - Authenticated (Contributor+) PHAR Deserialization
HighCVSS 8.8No exploitEPSS 2%themeisle · visualizerJul 18, 2022
- CVE-2024-131735Monitor
RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injection
HighCVSS 8.8No exploitEPSS 1%themeisle · rss aggregator by feedzyFeb 28, 2024
- CVE-2024-4732535Monitor
WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.7 - SQL Injection vulnerability
HighCVSS 8.8No exploitEPSS 0%themeisle · multiple page generatorOct 20, 2024
- CVE-2024-3573635Monitor
WordPress Visualizer plugin <= 3.11.1 - SQL Injection vulnerability
HighCVSS 8.8No exploitEPSS 0%themeisle · visualizerJun 8, 2024
- CVE-2024-3023535Monitor
WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%themeisle · multiple page generatorMar 26, 2024
- CVE-2022-4714335Monitor
WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%themeisle · multiple page generatorMar 14, 2023
- CVE-2024-3130135Monitor
WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%themeisle · multiple page generatorApr 12, 2024
- CVE-2024-1070532Monitor
Multiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrl
HighCVSS 8.1No exploitEPSS 0%themeisle · multiple page generatorJan 26, 2025
- CVE-2023-4752930Monitor
WordPress Cloud Templates & Patterns collection Plugin <= 1.2.2 is vulnerable to Sensitive Data Exposure
HighCVSS 7.5Proof of conceptEPSS 1%themeisle · cloud templates \& patterns collectionNov 23, 2023
- CVE-2024-1121930Monitor
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View
HighCVSS 7.5No exploitEPSS 1%themeisle · otter blocksNov 27, 2024
- CVE-2023-260728Monitor
Multiple Page Generator Plugin <= 3.3.17 - Authenticated (Administrator+) SQL Injection
HighCVSS 7.2No exploitEPSS 1%themeisle · multiple page generatorJun 9, 2023
- CVE-2024-2795128Monitor
WordPress Multiple Page Generator Plugin <= 3.4.0 - Auth. Remote Code Execution (RCE) vulnerability
HighCVSS 7.2No exploitEPSS 1%themeisle · multiple page generatorApr 3, 2024
- CVE-2021-2415826Monitor
Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Privilege Escalation
MediumCVSS 6.5No exploitEPSS 1%themeisle · orbit foxApr 5, 2021
- CVE-2022-157626Monitor
WP Maintenance Mode & Coming Soon < 2.4.5 - Subscribed Users Deletion via CSRF
MediumCVSS 6.5No exploitEPSS 1%themeisle · wp maintenance mode \& coming soonJul 11, 2022
- CVE-2024-131826Monitor
RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publication
MediumCVSS 6.5No exploitEPSS 1%themeisle · rss aggregator by feedzyFeb 28, 2024
- CVE-2019-1693125Monitor
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript w
MediumCVSS 6.1Proof of conceptEPSS 3%themeisle · visualizerOct 3, 2019
- CVE-2023-680525Monitor
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Fo
MediumCVSS 6.4No exploitEPSS 0%themeisle · rss aggregator by feedzyApr 17, 2024
- CVE-2023-225624Monitor
Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting
MediumCVSS 6.1Proof of conceptEPSS 1%themeisle · product addons \& fields for woocommerceMay 30, 2023
- CVE-2024-169124Monitor
Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Upload
MediumCVSS 6.1No exploitEPSS 0%themeisle · otter blocksMar 13, 2024
- CVE-2024-2795824Monitor
WordPress Visualizer plugin <= 3.10.5 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%themeisle · visualizerMar 17, 2024
- CVE-2024-272924Monitor
Otter Blocks < 2.6.6 - Contributor+ Stored XSS
MediumCVSS 6.1No exploitEPSS 0%themeisle · otter blocksApr 18, 2024