Export limit exceeded: 384084 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (23 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-1771 1 Hashthemes 1 Total 2026-04-08 4.3 Medium
The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the total_order_sections() function in all versions up to, and including, 2.1.59. This makes it possible for authenticated attackers, with subscriber-level access and above, to repeat sections on the homepage.
CVE-2024-10802 1 Hashthemes 1 Hash Elements 2026-04-08 5.3 Medium
The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_title_by_id() function in all versions up to, and including, 1.4.7. This makes it possible for unauthenticated attackers to retrieve draft post titles that should not be accessible to unauthenticated users.
CVE-2021-39333 1 Hashthemes 1 Hashthemes Demo Importer 2025-03-31 8.1 High
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents of wp-content/uploads.