Total
3 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-4114 | 1 Apusthemes | 1 Superio | 2025-04-10 | N/A | 5.4 MEDIUM |
|
The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks.
|
|||||
| CVE-2024-12296 | 1 Apusthemes | 1 Superio | 2025-02-20 | N/A | 8.8 HIGH |
|
The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_page_options' function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration f ...
Show More |
|||||
| CVE-2024-12213 | 1 Apusthemes | 1 Superio | 2025-02-20 | N/A | 9.8 CRITICAL |
|
The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.76. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites.
|
|||||