Skip to content
Noroxi

themeisle records

61 published records for vendor themeisle.

All records

61 records
  • A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

    CriticalCVSS 10.0Proof of conceptEPSS 39%

    themeisle · visualizerSep 30, 2019

  • Otter - Gutenberg Blocks < 2.2.6 - Author+ PHAR Deserialization

    HighCVSS 8.8No exploitEPSS 18%

    themeisle · otterMay 30, 2023

  • CVE-2024-3962
    39Monitor

    Product Addons & Fields for WooCommerce <= 32.0.18 - Unauthenticated Arbitrary File Upload via ppom_upload_file

    CriticalCVSS 9.8No exploitEPSS 1%

    themeisle · product addons \& fields for woocommerceApr 26, 2024

  • WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.19 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    themeisle · multiple page generatorOct 31, 2023

  • CVE-2022-2444
    36Monitor

    Visualizer: Tables and Charts Manager for WordPress <= 3.7.9 - Authenticated (Contributor+) PHAR Deserialization

    HighCVSS 8.8No exploitEPSS 2%

    themeisle · visualizerJul 18, 2022

  • CVE-2024-1317
    35Monitor

    RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injection

    HighCVSS 8.8No exploitEPSS 1%

    themeisle · rss aggregator by feedzyFeb 28, 2024

  • WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.7 - SQL Injection vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    themeisle · multiple page generatorOct 20, 2024

  • WordPress Visualizer plugin <= 3.11.1 - SQL Injection vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    themeisle · visualizerJun 8, 2024

  • WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    themeisle · multiple page generatorMar 26, 2024

  • WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    themeisle · multiple page generatorMar 14, 2023

  • WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    themeisle · multiple page generatorApr 12, 2024

  • Multiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrl

    HighCVSS 8.1No exploitEPSS 0%

    themeisle · multiple page generatorJan 26, 2025

  • WordPress Cloud Templates & Patterns collection Plugin <= 1.2.2 is vulnerable to Sensitive Data Exposure

    HighCVSS 7.5Proof of conceptEPSS 1%

    themeisle · cloud templates \& patterns collectionNov 23, 2023

  • Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View

    HighCVSS 7.5No exploitEPSS 1%

    themeisle · otter blocksNov 27, 2024

  • CVE-2023-2607
    28Monitor

    Multiple Page Generator Plugin <= 3.3.17 - Authenticated (Administrator+) SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    themeisle · multiple page generatorJun 9, 2023

  • WordPress Multiple Page Generator Plugin <= 3.4.0 - Auth. Remote Code Execution (RCE) vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    themeisle · multiple page generatorApr 3, 2024

  • Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Privilege Escalation

    MediumCVSS 6.5No exploitEPSS 1%

    themeisle · orbit foxApr 5, 2021

  • CVE-2022-1576
    26Monitor

    WP Maintenance Mode & Coming Soon < 2.4.5 - Subscribed Users Deletion via CSRF

    MediumCVSS 6.5No exploitEPSS 1%

    themeisle · wp maintenance mode \& coming soonJul 11, 2022

  • CVE-2024-1318
    26Monitor

    RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publication

    MediumCVSS 6.5No exploitEPSS 1%

    themeisle · rss aggregator by feedzyFeb 28, 2024

  • A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript w

    MediumCVSS 6.1Proof of conceptEPSS 3%

    themeisle · visualizerOct 3, 2019

  • CVE-2023-6805
    25Monitor

    RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Fo

    MediumCVSS 6.4No exploitEPSS 0%

    themeisle · rss aggregator by feedzyApr 17, 2024

  • CVE-2023-2256
    24Monitor

    Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting

    MediumCVSS 6.1Proof of conceptEPSS 1%

    themeisle · product addons \& fields for woocommerceMay 30, 2023

  • CVE-2024-1691
    24Monitor

    Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Upload

    MediumCVSS 6.1No exploitEPSS 0%

    themeisle · otter blocksMar 13, 2024

  • WordPress Visualizer plugin <= 3.10.5 - Reflected Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    themeisle · visualizerMar 17, 2024

  • CVE-2024-2729
    24Monitor

    Otter Blocks < 2.6.6 - Contributor+ Stored XSS

    MediumCVSS 6.1No exploitEPSS 0%

    themeisle · otter blocksApr 18, 2024