theme

Nexos Vulnerabilities

11 known security issues reported for the Nexos WordPress theme. Most recent disclosed Jun 28, 2020.

2 critical 2 medium

Running Nexos on your site? Check whether your installed version is affected.

Scan your site free

Nexos - Real Estate WordPress Theme <= 1.7 - SQL Injection

critical

The Nexos - Real Estate WordPress Theme theme for WordPress is vulnerable to generic SQL Injection via the ‘search_order’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

CVSS:
9.8
Affected:
up to 1.7
Fixed in:
1.8
Disclosed:
Jun 28, 2020

Nexos - Real Estate <= 1.7 - Reflected Cross-Site Scripting

medium

The Nexos - Real Estate theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_location’ parameter in versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 1.7
Fixed in:
1.8
Disclosed:
Jun 28, 2020

Nexos [nexos] <= 1.7

unknown

[en] The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.

Affected:
up to 1.7
Fixed in:
1.7
Disclosed:
Jun 28, 2020

CVE-2020-15363 on NVD →

Nexos [nexos] < 1.8

unknown

[en] The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Jun 28, 2020

CVE-2020-15364 on NVD →

Nexos [nexos] < 1.8

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress Nexos premium theme (versions <= 1.7).

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Jun 28, 2020

Nexos [nexos] < 1.8

unknown

SQL Injection (SQLi) vulnerability discovered by m0ze in WordPress Nexos premium theme (versions <= 1.7).

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Jun 28, 2020

Nexos [nexos] < 1.8

unknown

The Nexos - Real Estate theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search_location’ parameter in versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Jun 28, 2020

Nexos [nexos] < 1.8

unknown

The Nexos - Real Estate WordPress Theme theme for WordPress is vulnerable to generic SQL Injection via the ‘search_order’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Jun 28, 2020

Nexos - Real Estate WordPress Theme <= 1.7 - SQL Injection

critical

The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.

CVSS:
9.8
Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Jun 17, 2020

CVE-2020-15363 on NVD →

Nexos - Real Estate WordPress Theme < 1.8 - Cross-Site Scripting

medium

The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.

CVSS:
6.1
Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Jun 17, 2020

CVE-2020-15364 on NVD →

Nexos [nexos] < 1.6.1

unknown

----[]- SQL Injection: -[]---- Vulnerable &#039;id&#039; parameter is https://listing-themes.com/nexos-wp/wp-admin/admin.php?page=ownlisting_addlisting&amp;id=8 ----[]- Persistent XSS: -[]---- You need a new user account, then go to any property listing on the website and use &laquo;ENQUIRY FORM&raquo; on the righ...

Affected:
up to 1.6.1
Fixed in:
1.6.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database