Vendor
Inkthemes
Products
2
CVEs
4
Across products
4
Status
Private
Products
2- 2 CVEs
- 2 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10961 | Med | 0.40 | 6.1 | 0.01 | Sep 16, 2019 | The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter. | ||
| CVE-2022-3750 | Med | 0.31 | 4.7 | 0.00 | Nov 21, 2022 | The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation. | ||
| CVE-2023-25447 | Med | 0.28 | 4.3 | 0.00 | May 22, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Inkthemescom ColorWay theme <= 4.2.3 versions. | ||
| CVE-2022-1251 | Med | 0.28 | 4.3 | 0.00 | Aug 22, 2022 | The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request. |
- risk 0.40cvss 6.1epss 0.01
The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.
- risk 0.31cvss 4.7epss 0.00
The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation.
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Inkthemescom ColorWay theme <= 4.2.3 versions.
- risk 0.28cvss 4.3epss 0.00
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.