Vulnerabilities > Themeum

DATE CVE VULNERABILITY TITLE RISK
2024-06-11 CVE-2023-25799 Missing Authorization vulnerability in Themeum Tutor LMS
Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.
network
low complexity
themeum CWE-862
8.8
2024-06-07 CVE-2024-5438 Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.1 via the 'attempt_delete' function due to missing validation on a user controlled key.
network
low complexity
themeum CWE-639
4.3
2024-06-07 CVE-2024-4902 SQL Injection vulnerability in Themeum Tutor LMS
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
themeum CWE-89
7.2
2024-01-16 CVE-2023-0376 Cross-site Scripting vulnerability in Themeum Qubely
The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
network
low complexity
themeum CWE-79
5.4
2024-01-15 CVE-2023-6163 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
themeum CWE-79
4.8
2024-01-08 CVE-2023-6161 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
themeum CWE-79
6.1
2023-12-28 CVE-2023-50859 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through 2.1.6.
network
low complexity
themeum CWE-79
5.4
2023-12-15 CVE-2023-49829 Cross-site Scripting vulnerability in Themeum Tutor LMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a through 2.2.4.
network
low complexity
themeum CWE-79
4.8
2023-12-11 CVE-2023-5757 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
themeum CWE-79
4.8
2023-11-14 CVE-2023-47532 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
Unauth.
network
low complexity
themeum CWE-79
6.1