VYPR
Vendor

Themegrill

Products
8
CVEs
16
Across products
17
Status
Private

Products

8

Recent CVEs

16
  • CVE-2024-24882CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.02

    Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2.

  • CVE-2020-36333CriMay 5, 2021
    risk 0.59cvss 9.1epss 0.04

    themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

  • CVE-2024-10008HigOct 29, 2024
    risk 0.57cvss 8.8epss 0.01

    The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including,…

  • CVE-2020-36334HigMay 5, 2021
    risk 0.57cvss 8.8epss 0.01

    themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.

  • CVE-2024-43158HigNov 1, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4.

  • CVE-2024-10000MedOct 29, 2024
    risk 0.42cvss 6.4epss 0.00

    The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping.…

  • CVE-2024-0679MedJan 20, 2024
    risk 0.42cvss 6.5epss 0.01

    The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and…

  • CVE-2023-3345MedJul 31, 2023
    risk 0.42cvss 6.5epss 0.02

    The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

  • CVE-2024-39629MedAug 1, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.2.

  • CVE-2024-37432MedJul 22, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Esteem allows Stored XSS.This issue affects Esteem: from n/a through 1.5.0.

  • CVE-2024-33939MedMay 19, 2025
    risk 0.35cvss 5.3epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.3.

  • CVE-2024-43159MedNov 1, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.6.

  • CVE-2024-1462MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.01

    The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles and content when the site is in maintenance mode.

  • CVE-2024-1370MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.00

    The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers,…

  • CVE-2024-9218MedOct 2, 2024
    risk 0.33cvss 6.1epss 0.00

    The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up…

  • CVE-2024-43239MedAug 18, 2024
    risk 0.28cvss 4.3epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4.