Thème WordPress

Vulnérabilités Homey

Cette page rassemble les failles publiées pour Homey, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
1Critiques
5Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Homey

8 fiches

CVE-2025-31037 Moyenne · 6,1
Homey

Homey <= 2.4.5 – Reflected Cross-Site Scripting

The Homey theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-2.4.5

Correctif

Non indiqué

Publication

26/06/2025

CVE-2025-52834 Élevée · 7,5
Homey

Homey <= 2.4.5 – Unauthenticated SQL Injection

The Homey theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

*-2.4.5

Correctif

Non indiqué

Publication

24/06/2025

CVE-2025-1326 Moyenne · 4,3
Homey

Homey – Booking and Rentals WordPress Theme <= 2.4.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Reservation & Post Deletion

The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the homey_reservation_del() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.4.4

Correctif

2.4.5

Publication

01/05/2025

CVE-2025-1327 Moyenne · 4,3
Homey

Homey – Booking and Rentals WordPress Theme <= 2.4.4 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion

The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.4 via the 'homey_delete_user_account' action due to missing validation on a user controlled key. This makes it possible for…

Versions affectées

*-2.4.4

Correctif

2.4.5

Publication

01/05/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités