Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
themeisle vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2023-6798
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This...
Themeisle Rss Aggregator By Feedzy
5.4
CVSSv3
CVE-2023-6801
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and o...
Themeisle Rss Aggregator By Feedzy
5.4
CVSSv3
CVE-2022-4667
The RSS Aggregator by Feedzy WordPress plugin prior to 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be use...
Themeisle Rss Aggregator By Feedzy
4.3
CVSSv3
CVE-2020-36758
The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated mal...
Themeisle Rss Aggregator By Feedzy
6.5
CVSSv3
CVE-2022-1576
The WP Maintenance Mode & Coming Soon WordPress plugin prior to 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow malicious users to make a logged in admin perform such action via a CSRF attack
Themeisle Wp Maintenance Mode \\& Coming Soon
4.8
CVSSv3
CVE-2023-1839
The Product Addons & Fields for WooCommerce WordPress plugin prior to 32.0.6 does not sanitize and escape some of its setting fields, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability i...
Themeisle Product Addons \\& Fields For Woocommerce
5.4
CVSSv3
CVE-2023-4887
The Google Maps Plugin by Intergeo for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. Th...
Themeisle Google Maps Plugin By Intergeo
6.1
CVSSv3
CVE-2023-2256
The Product Addons & Fields for WooCommerce WordPress plugin prior to 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.
Themeisle Product Addons \\& Fields For Woocommerce
NA
CVE-2024-30235
Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a up to and including 3.4.0.
NA
CVE-2024-31301
Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a up to and including 3.4.0.
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »