StudioZen <= 1.6 - Multiple Vulnerabilities
medium
The StudioZen Theme for WordPress is vulnerable to full path disclosure, content spoofing, and cross-site scripting in versions up to, and including, 1.6. This is due to the inclusion of vulnerable jPlayer 2.2.23 scripts. This makes it possible for unauthenticated attackers to view the full path of the WordPress instal...
- CVSS:
- 6.1
- Affected:
- up to 1.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2013
StudioZen Theme (All Versions) - Cross-Site Scripting
medium
The StudioZen Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable version of jPlayer in all known versions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an...
- CVSS:
- 6.1
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2013
StudioZen [studiozen] < 100 (unfixed + closed)
unknown
The StudioZen Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable version of jPlayer in all known versions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an...
- Affected:
- up to 100
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2013
StudioZen [studiozen] <= 1.6 (unfixed)
unknown
The StudioZen Theme for WordPress is vulnerable to full path disclosure, content spoofing, and cross-site scripting in versions up to, and including, 1.6. This is due to the inclusion of vulnerable jPlayer 2.2.23 scripts. This makes it possible for unauthenticated attackers to view the full path of the WordPress instal...
- Affected:
- up to 1.6
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2013
StudioZen [studiozen] < 100 (unfixed)
unknown
The studiozen WordPress theme was affected by a Multiple Script Direct Request Path Disclosure security vulnerability.
- Affected:
- up to 100
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database