|
266491
|
7.5 |
HIGH
Network
|
accio_one_page_parallax_responsive_theme_project
|
accio_one_page_parallax_responsive_theme
|
The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values…
|
CWE-200
Information Exposure
|
CVE-2015-9484
|
2024-11-21 11:40 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266492
|
7.5 |
HIGH
Network
|
invento_\/_architecture_building_agency_template_project
|
invento_\/_architecture_building_agency_template
|
The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and…
|
CWE-200
Information Exposure
|
CVE-2015-9483
|
2024-11-21 11:40 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266493
|
7.5 |
HIGH
Network
|
car_dealer_\/_auto_dealer_responsive_project
|
car_dealer_\/_auto_dealer_responsive
|
The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email value…
|
CWE-200
Information Exposure
|
CVE-2015-9482
|
2024-11-21 11:40 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266494
|
7.5 |
HIGH
Network
|
diplomat_\|_political_project
|
diplomat_\|_political
|
The ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct…
|
CWE-200
Information Exposure
|
CVE-2015-9481
|
2024-11-21 11:40 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266495
|
7.5 |
HIGH
Network
|
robot-cpa
|
robotcpa
|
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
|
CWE-22
Path Traversal
|
CVE-2015-9480
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266496
|
9.8 |
CRITICAL
Network
|
advancedcustomfields
|
acf_fronted_display
|
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-9479
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266497
|
6.1 |
MEDIUM
Network
|
no-margin-for-error
|
prettyphoto
|
prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9478
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266498
|
8.8 |
HIGH
Network
|
vernissage_project
|
vernissage
|
The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
|
CWE-276
Incorrect Default Permissions
|
CVE-2015-9477
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266499
|
8.8 |
HIGH
Network
|
teardrop_project
|
teardrop
|
The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.
|
CWE-276
Incorrect Default Permissions
|
CVE-2015-9476
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266500
|
8.8 |
HIGH
Network
|
pont_project
|
pont
|
The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
|
CWE-276
Incorrect Default Permissions
|
CVE-2015-9475
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|