Thème WordPress
Vulnérabilités Woodmart
Cette page rassemble les failles publiées pour Woodmart, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Woodmart
18 fiches
Woodmart <= 8.5.3 – Unauthenticated Stored Cross-Site Scripting
The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-8.5.3
8.5.4
25/06/2026
Woodmart <= 8.3.8 – Unauthenticated PHP Object Injection
The Woodmart theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.3.8 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…
*-8.3.8
8.3.9
23/03/2026
WoodMart <= 8.3.9 – Unauthenticated Sensitive Information Exposure
The Woodmart theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
*-8.3.9
8.4.0
22/02/2026
WoodMart <= 8.3.7 – Unauthenticated Arbitrary Shortcode Execution
The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.3.7. This is due to the software allowing users to execute an action that does not properly validate a…
*-8.3.7
8.3.8
09/01/2026
WoodMart < 8.3.2 – Authenticated (Contributor+) Local File Inclusion
The WoodMart theme for WordPress is vulnerable to Local File Inclusion in versions up to 8.3.2. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing…
[*, 8.3.2)
8.3.2
14/10/2025
WoodMart < 8.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WoodMart theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 8.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject…
[*, 8.3.2)
8.3.2
10/10/2025
WoodMart – Multipurpose WooCommerce Theme <= 8.2.6 – Improper Input Validation Leading to Unauthenticated Cart Manipulation
The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient validation of the qty parameter in the woodmart_update_cart_item function. This makes it possible for…
*-8.2.6
8.2.7
25/07/2025
WoodMart <= 8.2.5 – Unauthenticated Post Disclosure
The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_query() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated…
*-8.2.5
8.2.6
10/07/2025
WoodMart <= 8.2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attribute in all versions up to, and including, 8.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-8.2.3
8.2.4
07/07/2025
WoodMart <= 8.2.3 – Authenticated (Contributor+) Local File Inclusion
The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and…
*-8.2.3
8.2.4
07/07/2025
Woodmart <= 8.2.3 – Unauthenticated Arbitrary Shortcode Execution
The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execute an action that does not properly validate a…
*-8.2.3
8.2.4
07/07/2025
WoodMart <= 8.0.3 – Unauthenticated Arbitrary Shortcode Execution
The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the software allowing users to execute an action that does not properly validate a value…
*-8.0.3
8.0.4
11/12/2024
WoodMart <= 7.2.4 – Reflected Cross-Site Scripting
The WoodMart theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-7.2.4
7.2.5
05/09/2023
WoodMart <= 7.2.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The WoodMart theme for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-7.2.1
7.2.2
11/05/2023
WoodMart <= 7.2.1 – Missing Authorization
The WoodMart theme for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on an unknown function in versions up to, and including, 7.2.1. This makes it possible for authenticated…
*-7.2.1
7.2.2
11/05/2023
WoodMart <= 7.1.1 – Missing Authorization to Shortcode Injection
The WoodMart theme for WordPress is vulnerable to unauthorized shortcode injection in versions up to, and including, 7.1.1. This makes it possible for unauthenticated attackers to inject arbitrary shortcodes. This is only present when the "Display results from…
*-7.1.1
7.1.2
01/03/2023
Woodmart <= 7.1.1 – Cross-Site Request Forgery to License Update
The Woodmart theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.1.1. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated…
*-7.1.1
7.1.2
01/03/2023
Woodmart <= 7.0.4 – Unauthenticated Arbitrary Content Injection
The Woodmart theme for WordPress is vulnerable to Arbitrary Content Injection in versions up to, and including, 7.0.4. The cause of this vulnerability is undisclosed at this time. However, this vulnerability makes it possible for unauthenticated attackers to…
*-7.0.4
7.1.1
16/02/2023
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.