Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
- Affected:
- up to 7.3.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2024
CVE-2023-46148 on NVD →
Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
- Affected:
- up to 7.3.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2024
CVE-2023-46146 on NVD →
Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)
unknown
[en] Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5.
- Affected:
- up to 7.3.3
- Fix:
- No patched version reported
- Disclosed:
- May 17, 2024
CVE-2023-46145 on NVD →
Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
- Affected:
- up to 7.3.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 20, 2023
CVE-2023-46149 on NVD →
Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
- Affected:
- up to 7.3.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 20, 2023
CVE-2023-46147 on NVD →
Themify Ultra <= 7.3.5 - Authenticated (Subscriber+) PHP Object Injection
high
The themify-ultra theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.3.5 via deserialization of untrusted input. This makes it possible for authenticated attackers with subscriber access and above to inject a PHP Object. If a POP chain is present via an additional plugin o...
- CVSS:
- 8.8
- Affected:
- up to 7.3.5
- Fixed in:
- 7.3.6
- Disclosed:
- Oct 17, 2023
CVE-2023-46147 on NVD →
Themify Ultra <= 7.3.5 - Privilege Escalation
high
The themify-ultra theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.5. This makes it possible for low-level attackers with subscriber-level access to elevate their privileges.
- CVSS:
- 8.8
- Affected:
- up to 7.3.5
- Fixed in:
- 7.3.6
- Disclosed:
- Oct 17, 2023
CVE-2023-46145 on NVD →
Themify Ultra <= 7.3.5 - Authenticated (Subscriber+) Arbitrary File Upload
high
The themify-ultra theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in during a file upload in all versions up to, and including, 7.3.5. This makes it possible for authenticated attackers with subscriber access or higher to upload arbitrary files on the affected site's serv...
- CVSS:
- 8.8
- Affected:
- up to 7.3.5
- Fixed in:
- 7.3.6
- Disclosed:
- Oct 17, 2023
CVE-2023-46149 on NVD →
Themify Ultra <= 7.3.5 - Missing Authorization
medium
The themify-ultra theme for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on an unknown function in all versions up to, and including, 7.3.5. This makes it possible for authenticated attackers with subscriber access or higher to utilize this functionality...
- CVSS:
- 5.4
- Affected:
- up to 7.3.5
- Fixed in:
- 7.3.6
- Disclosed:
- Oct 17, 2023
CVE-2023-46148 on NVD →
Themify Ultra <= 7.3.5 - Missing Authorization
medium
The Themify Ultra theme for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on one of its functions in versions up to, and including, 7.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to make use of this functionality.
- CVSS:
- 5.4
- Affected:
- up to 7.3.5
- Fixed in:
- 7.3.6
- Disclosed:
- Oct 17, 2023
CVE-2023-46146 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database