Skip to main content

Vendor archive

radiustheme CVEs

Beta · best-effort

24 CVEs tagged to vendor radiustheme0 Critical, 4 High, 20 Medium, 0 Low, 0 Unrated.

CVE-2025-7327

Published Jul 8, 2025

The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. This makes it possib…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1063

Published Feb 25, 2025

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-3635

Published Sep 30, 2024

The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Sto…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7888

Published Sep 13, 2024

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several function…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7418

Published Aug 29, 2024

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37520

Published Jul 9, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Ad…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1427

Published Jul 2, 2024

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attri…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35739

Published Jun 8, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme The Post Grid the-post-grid.This issue affects The Post Grid: fro…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3893

Published Apr 25, 2024

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the rtcl_f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1746

Published Apr 15, 2024

The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cros…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1352

Published Apr 9, 2024

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability ch…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1315

Published Apr 9, 2024

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. T…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1745

Published Mar 26, 2024

The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0836

Published Jan 31, 2024

The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-39923

Published Oct 3, 2023

Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 7.2.7 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-37387

Published Jul 18, 2023

Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-46853

Published May 23, 2023

Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 5.0.4 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-23685

Published Apr 4, 2023

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in RadiusTheme Portfolio – WordPress Portfolio plugin <= 2.8.10 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-2655

Published Sep 16, 2022

The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24742

Published Nov 1, 2021

The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for autho…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1