theme

Onair2 Vulnerabilities

1 known security issue reported for the Onair2 WordPress theme. Most recent disclosed Jun 28, 2021.

1 critical

Running Onair2 on your site? Check whether your installed version is affected.

Scan your site free

QT KenthaRadio < 2.0.2 & OnAir2 < 3.9.9.2 - Server-Side Request Forgery & Remote File Inclusion

critical

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery)...

CVSS:
9.8
Affected:
up to 3.9.9.2
Fixed in:
3.9.9.2
Disclosed:
Jun 28, 2021

CVE-2021-24472 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database