VYPR

Puzzles

by Themerex

CVEs (3)

  • CVE-2025-0837MedFeb 13, 2025
    risk 0.42cvss 6.4epss 0.00

    The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…

  • CVE-2024-13770Feb 13, 2025
    risk 0.00cvss epss 0.01

    The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of untrusted input 'view_more_posts' AJAX action. This makes it possible for…

  • CVE-2024-13769Feb 12, 2025
    risk 0.00cvss epss 0.00

    The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the 'theme_options_ajax_post_action' AJAX action in all versions up to, and including, 4.2.4. This makes it…