themeum Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with themeum products.
Products
- Tutor LMS – eLearning and online course solution37 vulnerabilities
- Tutor LMS19 vulnerabilities
- tutor_lms16 vulnerabilities
- Kirki – Freeform Page Builder, Website Builder & Customizer9 vulnerabilities
- Tutor LMS Pro9 vulnerabilities
- WP Crowdfunding9 vulnerabilities
- Kirki7 vulnerabilities
- Tutor LMS Elementor Addons6 vulnerabilities
- Qubely5 vulnerabilities
- Droip2 vulnerabilities
- Qubely – Advanced Gutenberg Blocks2 vulnerabilities
- Tutor LMS – Migration Tool2 vulnerabilities
- Right Way1 vulnerability
- Skillate1 vulnerability
- Tutor LMS BunnyNet Integration1 vulnerability
- tutor_lms_pro1 vulnerability
- tutorlms-migrationtool1 vulnerability
- WP Mega Menu1 vulnerability
- WP Page Builder (WordPress plugin)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-16974MEDIUM | Kirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta ShortcodeThe Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta Shortcode in all versions up to, and including, 6.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Aug 11, 2026 | CVSS6.4v3.1 | EPSS0.156% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15601MEDIUM | Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip)The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. This makes it possible for authenticated attackers, with custom-level access and above, to write arbitrary files on the server, which can allow for remote code execution. The install_app, update_app, and get_kirki_template_from_zip code paths accept a user-supplied app src value to construct… CWE-22Aug 1, 2026 | CVSS4.9v3.1 | EPSS0.767% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15444MEDIUM | Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' ParameterThe Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sen… CWE-89Jul 28, 2026 | CVSS4.9v3.1 | EPSS0.288% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65436MEDIUM | WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerabilityEditor Arbitrary File Deletion in Kirki <= 6.0.13 versions. CWE-22Jul 27, 2026 | CVSS6.8v3.1 | EPSS0.325% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-13464MEDIUM | Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' ParameterThe Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the full title, content, and excerpt of any WordPress post — including drafts, pending, privately published, password-protected, and trashed posts — regardless of author, by suppl… CWE-639Jul 24, 2026 | CVSS5.3v3.1 | EPSS0.343% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65531MEDIUM | WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in Qubely <= 1.8.14 versions. CWE-862Jul 23, 2026 | CVSS4.8v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1372MEDIUM | Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin ActivationThe Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization. CWE-862Jul 21, 2026 | CVSS4.3v3.1 | EPSS0.204% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15457MEDIUM | Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' ParameterThe Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability. CWE-22Jul 17, 2026 | CVSS4.9v3.1 | EPSS0.766% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15022MEDIUM | Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer ArrayThe Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive inf… CWE-89Jul 16, 2026 | CVSS6.5v3.1 | EPSS0.341% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57724CRITICAL | WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12. CWE-502Jul 13, 2026 | CVSS9.8v3.1 | EPSS0.375% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57725HIGH | WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11. CWE-79Jul 13, 2026 | CVSS7.1v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57726CRITICAL | WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12. CWE-89Jul 13, 2026 | CVSS9.3v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57727HIGH | WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13. CWE-862Jul 13, 2026 | CVSS7.5v3.1 | EPSS0.287% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57694MEDIUM | WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13. CWE-639Jul 13, 2026 | CVSS6.5v3.1 | EPSS0.237% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57680MEDIUM | WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) vulnerabilityUnauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions. CWE-639Jul 2, 2026 | CVSS6.5v3.1 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12472MEDIUM | Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' ParametersThe Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to send arbitrary HTML-injected emails — including phishing messages embedding a real, valid WordPress password-reset URL for the targeted user — to any registered user via the site… CWE-862Jul 2, 2026 | CVSS5.3v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12122MEDIUM | Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX ActionThe Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full builder metadata and rendered HTML of any kirki_symbol post — including unpublished drafts — by supplying a sequential WordPress post ID. CWE-862Jul 2, 2026 | CVSS5.3v3.1 | EPSS0.285% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-13443MEDIUM | Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment TitleThe Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in all versions up to, and including, 3.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Jul 1, 2026 | CVSS6.4v3.1 | EPSS0.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57627MEDIUM | WordPress Kirki plugin <= 6.0.11 - Server Side Request Forgery (SSRF) vulnerabilitySubscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions. CWE-918Jun 26, 2026 | CVSS4.9v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10736MEDIUM | Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' ParameterThe Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 3.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive… CWE-89Jun 18, 2026 | CVSS4.9v3.1 | EPSS0.489% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22332CRITICAL | WordPress Tutor LMS Pro plugin <= 3.9.6 - SQL Injection vulnerabilityUnauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. CWE-89Jun 17, 2026 | CVSS9.3v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22330HIGH | WordPress Right Way theme <= 4.0 - Local File Inclusion vulnerabilityUnauthenticated Local File Inclusion in Right Way <= 4.0 versions. CWE-98Jun 17, 2026 | CVSS8.1v3.1 | EPSS0.363% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22329HIGH | WordPress Skillate theme <= 1.2.10 - Reflected Cross Site Scripting (XSS) vulnerabilityUnauthenticated Cross Site Scripting (XSS) in Skillate <= 1.2.10 versions. CWE-79Jun 17, 2026 | CVSS7.1v3.1 | EPSS0.186% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40743MEDIUM | WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions. CWE-862Jun 15, 2026 | CVSS6.5v3.1 | EPSS0.252% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8206CRITICAL | Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address. CWE-269Jun 2, 2026 | CVSS9.8v3.1 | EPSS1.26% | PoCs6 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |