Description
Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 07 May 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:themify:woocommerce_product_filter:*:*:*:*:*:wordpress:*:* |
Sun, 27 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themify
Themify woocommerce Product Filter |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:themify:woocommerce_product_filter:-:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themify
Themify woocommerce Product Filter |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-27T15:03:11.060Z
Reserved: 2024-03-07T14:54:10.963Z
Link: CVE-2024-2278
Updated: 2024-08-01T19:11:52.117Z
Status : Analyzed
Published: 2024-04-01T05:15:08.053
Modified: 2025-05-07T01:07:01.500
Link: CVE-2024-2278
No data.
OpenCVE Enrichment
No data.
Weaknesses