Thème WordPress
Vulnérabilités Himer – Social Questions and Answers WordPress Theme
Cette page rassemble les failles publiées pour Himer – Social Questions and Answers WordPress Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Himer – Social Questions and Answers WordPress Theme
7 fiches
Himer – Social Questions and Answers <= 2.1.2 – Cross-Site Request Forgery to Arbitrary User Invites
The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or incorrect nonce validation on the wpqa_add_group_user AJAX action. This makes it possible for…
*-2.1.2
2.1.3
15/07/2024
Himer – Social Questions and Answers <= 2.1.0 – Authenticated (Subscriber+) Insecure Direct Object Reference
The Himer theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the wpqa_accept_invite AJAX action due to missing validation on a user controlled key. This makes it possible…
*-2.1.0
2.1.1
12/06/2024
Himer <= 2.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Himer theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom CSS code' setting in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.1.0
2.1.1
12/06/2024
Himer <= 2.1.0 – Cross-Site Request Forgery to Group Leave
The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the wpqa_leave_group AJAX action. This makes it possible for…
*-2.1.0
2.1.1
12/06/2024
Himer <= 2.1.0 – Cross-Site Request Forgery to Poll Voting
The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the wpqa_question_poll AJAX action. This makes it possible for…
*-2.1.0
2.1.1
12/06/2024
Himer <= 2.1.0 – Cross-Site Request Forgery to Private Group Join
The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the wpqa_join_group AJAX action. This makes it possible for…
*-2.1.0
2.1.1
12/06/2024
WPQA – Builder forms Addon For WordPress (<= 5.9.2), Himer (<= 1.9.3) and Discy (<= 5.5.3) – Authenticated (Subscriber+) Insecure Direct Object Reference
The WPQA – Builder forms Addon For WordPress plugin is vulnerable to insecure direct object reference in versions up to, and including, 5.9.2 along with the Himer (
*-1.9.3
Non indiqué
13/12/2022
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.