themehunk kayıtları
themehunk üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %43,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-862 Missing Authorization10
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2024-11972Kavram kanıtı | Hunk Companion < 1.9.0 - Unauthenticated Plugin Installationthemehunk · hunk companion · CWE-862 | Kritik9,8 | — | %54,5 | 31 Ara 2024 |
55Planlayın | CVE-2024-9061Kavram kanıtı | WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Addthemehunk · wp popup builder · CWE-94 | Kritik9,8 | — | %52,3 | 16 Eki 2024 |
42Planlayın | CVE-2024-9707Kavram kanıtı | Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activationthemehunk · hunk companion · CWE-862 | Kritik9,8 | — | %9,1 | 11 Eki 2024 |
39İzleyin | CVE-2022-38057İstismar yok | WordPress TH Advance Product Search plugin <= 1.2.1 - Unauthenticated Plugin Settings Reset vulnerabilitythemehunk · th advance product search · CWE-862 | Kritik9,8 | — | %0,6 | 25 Mar 2024 |
39İzleyin | CVE-2025-52816İstismar yok | WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerabilitythemehunk · zita · CWE-98 | Kritik9,8 | — | %0,5 | 27 Haz 2025 |
39İzleyin | CVE-2022-40218İstismar yok | WordPress TH Advance Product Search plugin <= 1.1.4 - Unauthenticated Plugin Settings Change vulnerabilitythemehunk · advance product search · CWE-862 | Kritik9,8 | — | %0,5 | 8 May 2024 |
36İzleyin | CVE-2024-10674Kavram kanıtı | Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activationthemehunk · th shop mania · CWE-862 | Yüksek8,8 | — | %1,7 | 9 Kas 2024 |
35İzleyin | CVE-2024-10673Kavram kanıtı | Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activationthemehunk · top store · CWE-862 | Yüksek8,8 | — | %1,2 | 9 Kas 2024 |
35İzleyin | CVE-2023-27431İstismar yok | WordPress Big Store Theme <= 1.9.3 is vulnerable to Cross Site Request Forgery (CSRF)themehunk · big store · CWE-352 | Yüksek8,8 | — | %0,3 | 12 Kas 2023 |
26İzleyin | CVE-2025-22644İstismar yok | WordPress Vayu Blocks – Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) vulnerabilitythemehunk · vayu blocks · CWE-79 | Orta6,5 | — | %0,3 | 27 Mar 2025 |
24İzleyin | CVE-2021-24967İstismar yok | Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site Scriptingthemehunk · contact form \& lead form elementor builder · CWE-79 | Orta6,1 | — | %1,2 | 27 Ara 2021 |
24İzleyin | CVE-2022-2404İstismar yok | WP Popup Builder < 1.2.9 - Reflected Cross-Site Scriptingthemehunk · wp popup builder · CWE-79 | Orta6,1 | — | %0,6 | 26 Eyl 2022 |
24İzleyin | CVE-2024-3637İstismar yok | Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Admin+ Stored XSSthemehunk · contact form \& lead form elementor builder · CWE-79 | Orta6,1 | — | %0,5 | 3 May 2024 |
21İzleyin | CVE-2025-30881İstismar yok | WordPress Big Store theme <= 2.0.8 - Broken Access Control vulnerabilitythemehunk · big store · CWE-862 | Orta5,4 | — | %0,4 | 27 Mar 2025 |
21İzleyin | CVE-2025-62902İstismar yok | WordPress WP Popup Builder plugin <= 1.3.8 - Sensitive Data Exposure vulnerabilitythemehunk · wp popup builder · CWE-497 | Orta5,3 | — | %0,3 | 26 Eki 2025 |
21İzleyin | CVE-2024-44049İstismar yok | WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Authenticated Cross Site Scripting (XSS) vulnerabilitythemehunk · gutenberg blocks · CWE-79 | Orta5,4 | — | %0,3 | 17 Eyl 2024 |
21İzleyin | CVE-2025-30990İstismar yok | WordPress ThemeHunk plugin <= 1.2.0 - Broken Access Control vulnerabilitythemehunk · mega menu · CWE-862 | Orta5,4 | — | %0,3 | 6 Haz 2025 |
21İzleyin | CVE-2023-28688İstismar yok | WordPress TH Variation Swatches plugin <= 1.2.7 - Cross-Site Request Forgery (CSRF) vulnerabilitythemehunk · variation swatches · CWE-352 | Orta5,4 | — | %0,2 | 9 Ara 2024 |
19İzleyin | CVE-2022-23179İstismar yok | Contact Form & Lead Form Elementor Builder < 1.7.0 - Multiple Admin+ Stored Cross-Site Scriptingthemehunk · contact form \& lead form elementor builder · CWE-79 | Orta4,8 | — | %0,5 | 16 Oca 2024 |
19İzleyin | CVE-2024-10475İstismar yok | Lead Form Builder < 1.9.8 - Admin+ Stored XSSthemehunk · contact form \& lead form elementor builder · CWE-79 | Orta4,8 | — | %0,3 | 15 May 2025 |
17İzleyin | CVE-2022-23180İstismar yok | Contact Form & Lead Form Elementor Builder Plugin < 1.7.4 - Multiple Subscriber+ Settings Updatethemehunk · contact form \& lead form elementor builder · CWE-862 | Orta4,3 | — | %0,5 | 16 Oca 2024 |
17İzleyin | CVE-2024-8434İstismar yok | Easy Mega Menu Plugin for WordPress – ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Settings Updatesthemehunk · mega menu · CWE-862 | Orta4,3 | — | %0,4 | 24 Eyl 2024 |
17İzleyin | CVE-2022-2405İstismar yok | WP Popup Builder < 1.3.0 - Subscriber+ Arbitrary Popup Deletionthemehunk · wp popup builder · CWE-352 | Orta4,3 | — | %0,3 | 26 Eyl 2022 |
- CVE-2024-1197255Planlayın
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
KritikCVSS 9,8Kavram kanıtıEPSS %54themehunk · hunk companion31 Ara 2024
- CVE-2024-906155Planlayın
WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add
KritikCVSS 9,8Kavram kanıtıEPSS %52themehunk · wp popup builder16 Eki 2024
- CVE-2024-970742Planlayın
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
KritikCVSS 9,8Kavram kanıtıEPSS %9themehunk · hunk companion11 Eki 2024
- CVE-2022-3805739İzleyin
WordPress TH Advance Product Search plugin <= 1.2.1 - Unauthenticated Plugin Settings Reset vulnerability
KritikCVSS 9,8İstismar yokEPSS %1themehunk · th advance product search25 Mar 2024
- CVE-2025-5281639İzleyin
WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1themehunk · zita27 Haz 2025
- CVE-2022-4021839İzleyin
WordPress TH Advance Product Search plugin <= 1.1.4 - Unauthenticated Plugin Settings Change vulnerability
KritikCVSS 9,8İstismar yokEPSS %0themehunk · advance product search8 May 2024
- CVE-2024-1067436İzleyin
Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
YüksekCVSS 8,8Kavram kanıtıEPSS %2themehunk · th shop mania9 Kas 2024
- CVE-2024-1067335İzleyin
Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
YüksekCVSS 8,8Kavram kanıtıEPSS %1themehunk · top store9 Kas 2024
- CVE-2023-2743135İzleyin
WordPress Big Store Theme <= 1.9.3 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0themehunk · big store12 Kas 2023
- CVE-2025-2264426İzleyin
WordPress Vayu Blocks – Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0themehunk · vayu blocks27 Mar 2025
- CVE-2021-2496724İzleyin
Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1themehunk · contact form \& lead form elementor builder27 Ara 2021
- CVE-2022-240424İzleyin
WP Popup Builder < 1.2.9 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1themehunk · wp popup builder26 Eyl 2022
- CVE-2024-363724İzleyin
Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Admin+ Stored XSS
OrtaCVSS 6,1İstismar yokEPSS %0themehunk · contact form \& lead form elementor builder3 May 2024
- CVE-2025-3088121İzleyin
WordPress Big Store theme <= 2.0.8 - Broken Access Control vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0themehunk · big store27 Mar 2025
- CVE-2025-6290221İzleyin
WordPress WP Popup Builder plugin <= 1.3.8 - Sensitive Data Exposure vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0themehunk · wp popup builder26 Eki 2025
- CVE-2024-4404921İzleyin
WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Authenticated Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0themehunk · gutenberg blocks17 Eyl 2024
- CVE-2025-3099021İzleyin
WordPress ThemeHunk plugin <= 1.2.0 - Broken Access Control vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0themehunk · mega menu6 Haz 2025
- CVE-2023-2868821İzleyin
WordPress TH Variation Swatches plugin <= 1.2.7 - Cross-Site Request Forgery (CSRF) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0themehunk · variation swatches9 Ara 2024
- CVE-2022-2317919İzleyin
Contact Form & Lead Form Elementor Builder < 1.7.0 - Multiple Admin+ Stored Cross-Site Scripting
OrtaCVSS 4,8İstismar yokEPSS %1themehunk · contact form \& lead form elementor builder16 Oca 2024
- CVE-2024-1047519İzleyin
Lead Form Builder < 1.9.8 - Admin+ Stored XSS
OrtaCVSS 4,8İstismar yokEPSS %0themehunk · contact form \& lead form elementor builder15 May 2025
- CVE-2022-2318017İzleyin
Contact Form & Lead Form Elementor Builder Plugin < 1.7.4 - Multiple Subscriber+ Settings Update
OrtaCVSS 4,3İstismar yokEPSS %1themehunk · contact form \& lead form elementor builder16 Oca 2024
- CVE-2024-843417İzleyin
Easy Mega Menu Plugin for WordPress – ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Settings Updates
OrtaCVSS 4,3İstismar yokEPSS %0themehunk · mega menu24 Eyl 2024
- CVE-2022-240517İzleyin
WP Popup Builder < 1.3.0 - Subscriber+ Arbitrary Popup Deletion
OrtaCVSS 4,3İstismar yokEPSS %0themehunk · wp popup builder26 Eyl 2022