Vulnerabilities (CVE)

Filtered by vendor Apusthemes
Filtered by product Superio
Angry Yack Logo
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-4114 1 Apusthemes 1 Superio 2025-04-10 N/A 5.4 MEDIUM
The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks.
CVE-2024-12296 1 Apusthemes 1 Superio 2025-02-20 N/A 8.8 HIGH
The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_page_options' function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration f ...

Show More

CVE-2024-12213 1 Apusthemes 1 Superio 2025-02-20 N/A 9.8 CRITICAL
The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites.