by Ivan Sorkin | Feb 17, 2026 | Themes
Attack Vectors Exzo (Electronics eCommerce WordPress WooCommerce Theme) versions up to and including 1.2.4 are affected by CVE-2025-69393, a Medium severity issue (CVSS 5.3) involving missing authorization. In practical terms, this means an attacker can reach at least...
by Ivan Sorkin | Feb 14, 2026 | Themes
Attack Vectors Critical severity (CVSS 9.8) vulnerability CVE-2025-32595 affects the Krowd – Crowdfunding & Charity WordPress Theme (slug: krowd) in versions up to and including 1.4.1. This issue is described as an Unauthenticated Local File Inclusion (LFI),...
by Ivan Sorkin | Feb 13, 2026 | Themes
Attack Vectors CVE-2024-43334 is a Medium severity (CVSS 6.1) reflected cross-site scripting (XSS) issue affecting the Paroti – Nonprofit Charity WordPress Theme (slug: paroti) across various versions. Because the attack is reflected, it typically relies on...
by Ivan Sorkin | Feb 12, 2026 | Themes
Attack Vectors High severity vulnerability (CVSS 8.8) reported as CVE-2025-6990 affects the KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme (slug: kallyas-2) in versions up to and including 4.24.0. The issue enables authenticated Remote Code Execution...
by Ivan Sorkin | Feb 12, 2026 | Themes
Attack Vectors CVE-2024-43334 is a Medium severity reflected cross-site scripting (XSS) issue affecting the Paroti – Nonprofit Charity WordPress Theme (slug: paroti) and other “gavias” themes in various versions. Because this is a reflected XSS scenario, the...
by Ivan Sorkin | Feb 12, 2026 | Themes
Attack Vectors CVE-2024-43334 is a Medium-severity (CVSS 6.1) Reflected Cross-Site Scripting (XSS) vulnerability affecting Paroti – Nonprofit Charity WordPress Theme (slug: paroti) and other themes by gavias in various versions. Because exploitation does not...
Recent Comments