Vulnerabilities > Thememakers
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-02-27 | CVE-2025-1282 | Path Traversal vulnerability in Thememakers CAR Dealer Automotive The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_post_photo() and add_car() functions in all versions up to, and including, 1.6.3. | 8.8 |
2025-02-27 | CVE-2025-1690 | Cross-site Scripting vulnerability in Thememakers Stripe Checkout The ThemeMakers Stripe Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stripe' shortcode in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-27 | CVE-2025-1689 | Cross-site Scripting vulnerability in Thememakers Paypal Checkout The ThemeMakers PayPal Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |