Extension WordPress
Vulnérabilités Theme My Login
Cette page rassemble les failles publiées pour Theme My Login, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Theme My Login
4 fiches
Theme My Login <= 7.1.12 – Missing Authorization
The Theme My Login plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.1.12. This makes it possible for unauthenticated attackers to perform an…
*-7.1.12
7.1.13
26/09/2025
Theme My Login <= 7.1.7 – Cross-Site Request Forgery to Settings Update
The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.1.7. This is due to missing or incorrect nonce validation on the tml_admin_save_ms_settings() function. This makes it possible…
*-7.1.7
7.1.8
15/08/2024
Theme My Login <= 7.1.6 – Missing Authorization to Notice Dismissal
The Theme My Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tml_admin_ajax_dismiss_notice() function in all versions up to, and including, 7.1.6. This makes it possible for authenticated…
*-7.1.6
7.1.7
15/04/2024
Theme My Login <= 6.3.9 – Local File Inclusion
The Theme My Login plugin for WordPress is vulnerable to Local File Inclusion in versions before 6.3.10 via the login_template attribute found in the theme-my-login shortcode. This allows authenticated attackers to include and execute arbitrary files on the…
[*, 6.3.10)
6.3.10
30/06/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.