VYPR
Vendor

Inkthemes

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2016-10961MedSep 16, 2019
    risk 0.40cvss 6.1epss 0.01

    The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.

  • CVE-2022-3750MedNov 21, 2022
    risk 0.31cvss 4.7epss 0.00

    The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation.

  • CVE-2023-25447MedMay 22, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Inkthemescom ColorWay theme <= 4.2.3 versions.

  • CVE-2022-1251MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.