plugin

Boombox Theme Extensions Vulnerabilities

2 known security issues reported for the Boombox Theme Extensions WordPress plugin. Most recent disclosed Mar 18, 2025.

2 high

Running Boombox Theme Extensions on your site? Check whether your installed version is affected.

Scan your site free

BoomBox Theme Extensions <= 1.8.0 - Authenticated (Subscriber+) Privilege Escalation via Password Reset/Account Takeover in boombox_ajax_reset_password

high

The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.8.0. This is due to the plugin not properly validating a user's identity prior to updating their password through the 'boombox_ajax_reset_password' function. This makes it...

CVSS:
8.8
Affected:
up to 1.8.0
Fixed in:
1.8.1
Disclosed:
Mar 18, 2025

CVE-2024-12295 on NVD →

BoomBox Theme Extensions <= 1.8.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode

high

The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8.0 via the 'boombox_listing' shortcode 'type' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary fil...

CVSS:
8.8
Affected:
up to 1.8.0
Fixed in:
1.8.1
Disclosed:
Feb 3, 2025

CVE-2024-12859 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database