Products

Showing 3 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
colorlib vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Coming Soon & Maintenance Mode by Colorlib <= 1.0.99 - Information Exposure

The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page contents via REST API thus bypassing maintenance mode protection provided by the plugin.

CWE-284Mar 20, 2024
CVSS5.3v3.1EPSS0.533%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Epsilon Framework Themes (Various Versions) - Function Injection

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible

CWE-94Jun 7, 20231 related artifact
CVSS9.8v3.1EPSS65.3%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

colorlib fancybox Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

CWE-79Feb 17, 2015
CVSS4.3v2.0EPSS6.41%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX