Vulnerabilidades em Themeum

118 resultados
Análise Vexday

Themeum apresenta 48 vulnerabilidades registradas, com 11 publicadas nos últimos 90 dias, indicando cadência moderada de descobertas. Nenhuma vulnerabilidade está sob ataque ativo no momento, embora 4 sejam críticas; a fraqueza predominante é injeção de conteúdo (CWE-79), típica de aplicações web. O risco atual é gerenciável, mas a presença de críticas e o padrão recente de descobertas justificam monitoramento contínuo.

CVE-2024-4279MEDIUMTutor LMS – eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course DeletionEPSS 0.4%CVE-2024-1798MEDIUMTutor LMS – Migration Tool <= 2.2.0 - Missing Authorization in tutor_lp_export_xmlEPSS 0.4%CVE-2025-1508MEDIUMWP Crowdfunding <= 2.1.14 - Missing Authorization to Authenticated (Subscriber+) Post Content DownloadEPSS 0.4%CVE-2026-8096MEDIUMKirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Submission Data Exposure via 'kirki_wp_admin_get_apis' ActionEPSS 0.4%CVE-2024-43142MEDIUMWordPress Tutor LMS plugin <= 2.7.3 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-57726CRITICALWordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerabilityEPSS 0.4%CVE-2026-57727HIGHWordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2023-49829MEDIUMWordPress Tutor LMS Plugin <= 2.2.4 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2024-3994MEDIUMTutor LMS – eLearning and online course solution <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' ShortcodeEPSS 0.4%CVE-2024-1133MEDIUMTutor LMS <= 2.6.0 - Missing AuthorizationEPSS 0.4%CVE-2026-3358MEDIUMTutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course EnrollmentEPSS 0.4%CVE-2024-10117MEDIUMWP Crowdfunding <= 2.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpcf_donate ShortcodeEPSS 0.4%CVE-2023-47532MEDIUMWordPress WP Crowdfunding Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2026-22330HIGHWordPress Right Way theme <= 4.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2024-43937MEDIUMWordPress WP Crowdfunding plugin <= 2.1.10 - Settings Change vulnerabilityEPSS 0.4%CVE-2026-3371MEDIUMTutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content ModificationEPSS 0.4%CVE-2026-1375HIGHTutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and DeletionEPSS 0.4%CVE-2025-6184HIGHTutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL InjectionEPSS 0.4%CVE-2026-13443MEDIUMTutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment TitleEPSS 0.4%CVE-2024-5784HIGHTutor LMS Pro <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Insecure Direct Object ReferenceEPSS 0.4%