Vulnerabilities > Themify

DATE CVE VULNERABILITY TITLE RISK
2025-01-22 CVE-2024-13319 Cross-site Scripting vulnerability in Themify Builder
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5.
network
low complexity
themify CWE-79
6.1
2024-12-31 CVE-2024-56216 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Themify Builder
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themify Themify Builder allows PHP Local File Inclusion.This issue affects Themify Builder: from n/a through 7.6.3.
network
low complexity
themify CWE-829
6.5
2024-12-13 CVE-2024-12414 Cross-Site Request Forgery (CSRF) vulnerability in Themify Store Locator
The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.9.
network
low complexity
themify CWE-352
4.3
2024-11-18 CVE-2024-52423 Cross-site Scripting vulnerability in Themify Builder
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify Builder allows Stored XSS.This issue affects Themify Builder: from n/a through 7.6.3.
network
low complexity
themify CWE-79
5.4
2024-10-06 CVE-2024-44046 Cross-site Scripting vulnerability in Themify Woocommerce Product Filter
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify – WooCommerce Product Filter allows Stored XSS.This issue affects Themify – WooCommerce Product Filter: from n/a through 1.5.1.
network
low complexity
themify CWE-79
4.8
2024-10-05 CVE-2024-9385 Cross-site Scripting vulnerability in Themify Builder
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.2.
network
low complexity
themify CWE-79
6.1
2024-08-22 CVE-2024-7836 Incorrect Authorization vulnerability in Themify Builder
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1.
network
low complexity
themify CWE-863
4.3
2024-08-12 CVE-2024-43133 Cross-site Scripting vulnerability in Themify Shortcodes
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify Shortcodes allows Stored XSS.This issue affects Themify Shortcodes: from n/a through 2.1.1.
network
low complexity
themify CWE-79
5.4
2024-06-21 CVE-2024-6027 SQL Injection vulnerability in Themify Product Filter
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
themify CWE-89
7.5
2024-06-19 CVE-2023-46146 Missing Authorization vulnerability in Themify Ultra
Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
network
low complexity
themify CWE-862
8.8