CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Weavertheme 1Weaver Xtreme Theme Support Jun 17, 2026 Jun 5, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and including, 6.4 due to insufficient input sanitization and output...Show more |
1Weavertheme 1Weaver Xtreme Theme Support Jun 17, 2026 Jan 11, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions up to, and including, 6.3.0 due to insufficient input sanitization and output escaping on user suppl...Show more |
1Weavertheme 1Weaver Xtreme Theme Support Jun 17, 2026 Oct 16, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suita...Show more |
1Weavertheme 1Weaver Xtreme Theme Support Jun 17, 2026 Apr 24, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users...Show more |