theme

Photocrati Theme Vulnerabilities

8 known security issues reported for the Photocrati Theme WordPress theme. Most recent disclosed Mar 5, 2015.

2 critical 1 medium

Running Photocrati Theme on your site? Check whether your installed version is affected.

Scan your site free

Photocrati [photocrati-theme] < 5.0 (unfixed)

unknown

[en] SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter.

Affected:
up to 5.0
Fix:
No patched version reported
Disclosed:
Mar 5, 2015

CVE-2015-2216 on NVD →

Photocrati [photocrati-theme] < 5.0

unknown

[en] Cross-site scripting (XSS) vulnerability in photocrati-gallery/ecomm-sizes.php in the Photocrati theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the prod_id parameter.

Affected:
up to 5.0
Fixed in:
5.0
Disclosed:
Jan 13, 2015

CVE-2014-100016 on NVD →

Photocrati [photocrati-theme] < 1.1

unknown

Because of this vulnerability, the attackers can obtain sensitive information via an invalid upload request. Update the theme.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Photocrati <= 4.8.0 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in photocrati-gallery/ecomm-sizes.php in the Photocrati theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the prod_id parameter.

CVSS:
6.1
Affected:
up to 4.8.0
Fixed in:
4.8.1
Disclosed:
Jan 29, 2014

CVE-2014-100016 on NVD →

Photocrati (Unknown Versions) - Multiple Vulnerabilities

critical

The Photocrati Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all versions. This is due to inclusion of a vulnerable version of jPlayer. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser, create fak...

CVSS:
10
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Apr 24, 2013

Photocrati [photocrati-theme] < 100 (unfixed + closed)

unknown

The Photocrati Theme for WordPress is vulnerable to Cross-Site Scripting, Content Spoofing, and Path Traversal in all versions. This is due to inclusion of a vulnerable version of jPlayer. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser, create fak...

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Apr 24, 2013

PhotoCrati Theme <= 4.0 - SQL Injection

critical

SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme up to and including version 4.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter.

CVSS:
9.8
Affected:
up to 4.0
Fixed in:
4.1
Disclosed:
Sep 23, 2011

CVE-2015-2216 on NVD →

Photocrati [photocrati-theme] < 100 (unfixed)

unknown

The photocrati-theme WordPress theme was affected by a Full Path Disclosure security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database