cbcvebase.

G5Theme April Framework vulnerabilities

3 known vulnerabilities affecting g5theme/april_framework.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2024-13418P2HIGHCVSS 8.8≤ 5.12025-05-02
CVE-2024-13418 [HIGH] CWE-434 CVE-2024-13418: Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missi Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files that can make remote code execution possible. This issue was
nvd
CVE-2024-13419P4MEDIUMCVSS 5.4≤ 5.12025-05-02
CVE-2024-13419 [MEDIUM] CWE-862 CVE-2024-13419: Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Si Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings whi
nvd
CVE-2024-13420P4MEDIUMCVSS 4.3≤ 5.12025-05-02
CVE-2024-13420 [MEDIUM] CWE-94 CVE-2024-13420: Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above,
nvd
G5Theme April Framework vulnerabilities | cvebase