machothemes Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with machothemes products.
Products
- Antreas1 vulnerability
- CPO Companion1 vulnerability
- image_photo_gallery_final_tiles_grid1 vulnerability
- MedZone Lite1 vulnerability
- NatureMag Lite1 vulnerability
- NewsMag1 vulnerability
- Regina Lite1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-3710MEDIUM | Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSSThe Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin CWE-79Jul 13, 2024 | CVSS6.8v3.1 | EPSS0.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33916MEDIUM | WordPress CPO Companion plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MachoThemes CPO Companion allows Stored XSS.This issue affects CPO Companion: from n/a through 1.1.0. CWE-79May 3, 2024 | CVSS6.5v3.1 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36708CRITICAL | Epsilon Framework Themes (Various Versions) - Function InjectionThe following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible … | CVSS9.8v3.1 | EPSS65.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |