Products

Showing 2 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
mageewp vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

OneTone theme for WordPress includes/theme-functions.php Vulnerability

includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.

Apr 3, 20201 related artifact
CVSS5.3v3.1EPSS2.36%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

mageewp onetone Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.

CWE-79Apr 3, 20201 related artifact
CVSS6.1v3.1EPSS1.22%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX