Vulnerabilities in Themeum
118 resultsVexday analysis
Themeum apresenta 48 vulnerabilidades registradas, com 11 publicadas nos últimos 90 dias, indicando cadência moderada de descobertas. Nenhuma vulnerabilidade está sob ataque ativo no momento, embora 4 sejam críticas; a fraqueza predominante é injeção de conteúdo (CWE-79), típica de aplicações web. O risco atual é gerenciável, mas a presença de críticas e o padrão recente de descobertas justificam monitoramento contínuo.
CVE-2024-37256HIGHWordPress Tutor LMS plugin <= 2.7.1 - SQL Injection vulnerabilityEPSS 0.6%CVE-2026-15022MEDIUMTutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer ArrayEPSS 0.6%CVE-2026-8073HIGHKirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIPEPSS 0.6%CVE-2026-57724CRITICALWordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2024-4223CRITICALTutor LMS <= 2.7.0 - Missing AuthorizationEPSS 0.5%CVE-2024-4318HIGHTutor LMS <= 2.7.0 - Authenticated (Instructor+) SQL InjectionEPSS 0.5%CVE-2024-1128MEDIUMTutor LMS <= 2.6.0 - Authenticated(Student+) HTML Injection via Q&AEPSS 0.5%CVE-2026-6080MEDIUMTutor LMS <= 3.9.8 - Authenticated (Admin+) SQL Injection via 'date' ParameterEPSS 0.5%CVE-2024-4902HIGHTutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL InjectionEPSS 0.5%CVE-2026-12122MEDIUMKirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX ActionEPSS 0.5%CVE-2026-10736MEDIUMTutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' ParameterEPSS 0.5%CVE-2024-53816MEDIUMWordPress Tutor LMS Elementor Addons plugin <= 2.1.5 - Broken Access Control vulnerabilityEPSS 0.5%CVE-2025-13673HIGHTutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_codeEPSS 0.5%CVE-2026-5502MEDIUMTutor LMS <= 3.9.8 - Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_orderEPSS 0.5%CVE-2024-3553MEDIUMTutor LMS <= 2.6.2 - Missing Authorization to Unauthenticated Limited Options UpdateEPSS 0.5%CVE-2023-25799HIGHWordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilitiesEPSS 0.5%CVE-2024-43282HIGHWordPress Tutor LMS plugin <= 2.7.2 - SQL Injection vulnerabilityEPSS 0.4%CVE-2026-16759MEDIUMTutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST ParametersEPSS 0.4%CVE-2022-40963MEDIUMWordPress WP Page Builder plugin <= 1.2.6 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilitiesEPSS 0.4%CVE-2024-1502MEDIUMTutor LMS – eLearning and online course solution <= 2.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post DeletionEPSS 0.4%