Skip to main content

Vendor archive

themeum CVEs

Beta · best-effort

80 CVEs tagged to vendor themeum2 Critical, 19 High, 58 Medium, 1 Low, 0 Unrated.

CVE-2025-6680

Published Oct 25, 2025

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3. This makes i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11564

Published Oct 25, 2025

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check while verifying webh…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5835

Published Jul 25, 2025

The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis() function in all versions up…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5831

Published Jul 25, 2025

The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function in all versions up to, and ex…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1508

Published Mar 12, 2025

The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and incl…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13228

Published Mar 11, 2025

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_conten…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-26767

Published Feb 16, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9601

Published Feb 14, 2025

The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up to, and inclu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41870

Published Dec 13, 2024

Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-11911

Published Dec 13, 2024

The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11910

Published Dec 13, 2024

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search block in all versions up to, and including, 2.1.15 due to insu…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53816

Published Dec 9, 2024

Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons.This issue affects Tutor LMS Elementor Addons: from n/a through <= 2.1.5.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10400

Published Nov 21, 2024

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10393

Published Nov 21, 2024

The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10897

Published Nov 15, 2024

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_etlms_dependency_plugin() fu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43937

Published Nov 1, 2024

Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43142

Published Nov 1, 2024

Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through 2.7…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10117

Published Oct 26, 2024

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate shortcode in all versions up to, and including, 2.1.11 due to in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2919

Published Sep 10, 2024

The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5784

Published Aug 30, 2024

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43955

Published Aug 29, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows File Manipulation.This issue affects Droip: from n/a through 1…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-43954

Published Aug 29, 2024

Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Droip: from n/a through 1.1.1.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39645

Published Aug 26, 2024

Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5576

Published Aug 20, 2024

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carousel_skin' attribute within the plugin's Course Carousel widge…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43282

Published Aug 18, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 80 CVEsPage 1 of 4