Thème WordPress
Vulnérabilités Enfold – Responsive Multi-Purpose Theme
Cette page rassemble les failles publiées pour Enfold – Responsive Multi-Purpose Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Enfold – Responsive Multi-Purpose Theme
11 fiches
Enfold – Responsive Multi-Purpose Theme <= 7.1.4 – Reflected Cross-Site Scripting
The Enfold – Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-7.1.4
7.1.5
01/06/2026
Enfold <= 7.1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Enfold theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-7.1.3
7.1.4
20/01/2026
Enfold <= 7.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Enfold theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-7.1.2
7.1.3
21/10/2025
Enfold <= 6.0.9 – Authenticated (Subscriber+) Server-Side Request Forgery via attachment_id
The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 via the 'attachment_id' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web…
*-6.0.9
7.0
24/02/2025
Enfold <= 6.0.9 – Missing Authorization to Sensitive Information Disclosure in avia-export-class.php
The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to export all…
*-6.0.9
7.0
24/02/2025
Enfold <= 6.0.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via wrapper_class and class Parameters
The Enfold – Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' parameters in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping. This…
*-6.0.3
6.0.4
29/08/2024
Enfold <= 5.6.9 – Reflected Cross-Site Scripting
The Enfold theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-5.6.9
5.6.10
20/06/2024
Enfold <= 5.6.4 – Reflected Cross-Site Scripting
The Enfold – Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 5.6.4 due to insufficient input sanitization and output escaping. This makes it…
*-5.6.4
5.6.5
23/11/2023
Enfold – Responsive Multi-Purpose Theme < 4.8.4 – Reflected Cross-Site Scripting
The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.
[*, 4.8.4)
4.8.4
18/10/2021
Enfold – Responsive Multi-Purpose Theme < 4.2.1 – Information Exposure
The Enfold Theme for WordPress is vulnerable the information exposure in versions up to, and including, 4.2.
[*, 4.2.1)
4.2.1
18/01/2018
Enfold < 3.0.1 – Unspecified Vulnerability
Unspecified vulnerability in the folder framework in the Enfold theme before 3.0.1 for WordPress has unknown impact and attack vectors.
[*, 3.0.1)
3.0.1
07/10/2014
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.