theme

Superlist Vulnerabilities

4 known security issues reported for the Superlist WordPress theme. Most recent disclosed Dec 12, 2019.

1 medium

Running Superlist on your site? Check whether your installed version is affected.

Scan your site free

Superlist [superlist] < 2.9.3

unknown

Persistent Cross-Site Scripting (XSS) vulnerability found by SUBVΞRSΛ in WordPress Superlist premium theme (versions <= 2.9.2).

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Dec 12, 2019

Superlist - Directory WordPress Theme | Directory & Listings <= 2.9.2 - Stored Cross-Site Scripting

medium

TheSuperlist - Directory WordPress Theme | Directory & Listings theme for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-...

CVSS:
6.4
Affected:
up to 2.9.2
Fix:
No patched version reported
Disclosed:
Feb 12, 2019

Superlist [superlist] <= 2.9.2 (unfixed)

unknown

TheSuperlist - Directory WordPress Theme | Directory & Listings theme for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-...

Affected:
up to 2.9.2
Fix:
No patched version reported
Disclosed:
Feb 12, 2019

Superlist [superlist] <= 2.9.2 (unfixed)

unknown

Persistent XSS was discovered in the &#039;Superlist - Directory WordPress Theme&#039;, the version tested was v2.9.2. Edit (WPScanTeam): December 2nd, 2019 - Envato Contacted December 2nd, 2019 - Envato Investigating December 12th, 2019 - No updates, disclosing

Affected:
up to 2.9.2
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database