VYPR

Template Kit – Import

by WordPress

CVEs (2)

  • CVE-2021-4330HigMar 7, 2023
    risk 0.57cvss 8.8epss 0.02

    The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting uploaded Zip files in the installFreeTemplateKit and uploadTemplateKitZipFile functions. This…

  • CVE-2024-2334MedApr 9, 2024
    risk 0.35cvss 6.4epss 0.00

    The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload functionality in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…