Skip to main content

Vendor/product archive

themeeditor / theme_editor CVEs

Beta · best-effort

2 CVEs tagged to themeeditor / theme_editor0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-2440

Published Aug 29, 2024

The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it poss…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24154

Published Apr 5, 2021

The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitra…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1