theme

Themify Ultra Vulnerabilities

10 known security issues reported for the Themify Ultra WordPress theme. Most recent disclosed Jun 19, 2024.

3 high 2 medium

Running Themify Ultra on your site? Check whether your installed version is affected.

Scan your site free

Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Affected:
up to 7.3.3
Fix:
No patched version reported
Disclosed:
Jun 19, 2024

CVE-2023-46148 on NVD →

Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Affected:
up to 7.3.3
Fix:
No patched version reported
Disclosed:
Jun 19, 2024

CVE-2023-46146 on NVD →

Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)

unknown

[en] Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5.

Affected:
up to 7.3.3
Fix:
No patched version reported
Disclosed:
May 17, 2024

CVE-2023-46145 on NVD →

Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Affected:
up to 7.3.3
Fix:
No patched version reported
Disclosed:
Dec 20, 2023

CVE-2023-46149 on NVD →

Themify Ultra [themify-ultra] <= 7.3.3 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Affected:
up to 7.3.3
Fix:
No patched version reported
Disclosed:
Dec 20, 2023

CVE-2023-46147 on NVD →

Themify Ultra <= 7.3.5 - Authenticated (Subscriber+) PHP Object Injection

high

The themify-ultra theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.3.5 via deserialization of untrusted input. This makes it possible for authenticated attackers with subscriber access and above to inject a PHP Object. If a POP chain is present via an additional plugin o...

CVSS:
8.8
Affected:
up to 7.3.5
Fixed in:
7.3.6
Disclosed:
Oct 17, 2023

CVE-2023-46147 on NVD →

Themify Ultra <= 7.3.5 - Privilege Escalation

high

The themify-ultra theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.5. This makes it possible for low-level attackers with subscriber-level access to elevate their privileges.

CVSS:
8.8
Affected:
up to 7.3.5
Fixed in:
7.3.6
Disclosed:
Oct 17, 2023

CVE-2023-46145 on NVD →

Themify Ultra <= 7.3.5 - Authenticated (Subscriber+) Arbitrary File Upload

high

The themify-ultra theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in during a file upload in all versions up to, and including, 7.3.5. This makes it possible for authenticated attackers with subscriber access or higher to upload arbitrary files on the affected site's serv...

CVSS:
8.8
Affected:
up to 7.3.5
Fixed in:
7.3.6
Disclosed:
Oct 17, 2023

CVE-2023-46149 on NVD →

Themify Ultra <= 7.3.5 - Missing Authorization

medium

The themify-ultra theme for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on an unknown function in all versions up to, and including, 7.3.5. This makes it possible for authenticated attackers with subscriber access or higher to utilize this functionality...

CVSS:
5.4
Affected:
up to 7.3.5
Fixed in:
7.3.6
Disclosed:
Oct 17, 2023

CVE-2023-46148 on NVD →

Themify Ultra <= 7.3.5 - Missing Authorization

medium

The Themify Ultra theme for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on one of its functions in versions up to, and including, 7.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to make use of this functionality.

CVSS:
5.4
Affected:
up to 7.3.5
Fixed in:
7.3.6
Disclosed:
Oct 17, 2023

CVE-2023-46146 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database