theme

Uncode Vulnerabilities

7 known security issues reported for the Uncode WordPress theme. Most recent disclosed Aug 26, 2025.

1 high 3 medium

Running Uncode on your site? Check whether your installed version is affected.

Scan your site free

Uncode < 2.9.4.4 - Reflected Cross-Site Scripting

medium

The Uncode theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 2.9.4.4 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to 2.9.4.4
Fixed in:
2.9.4.4
Disclosed:
Aug 26, 2025

CVE-2025-48107 on NVD →

Uncode [uncode] < 2.9.1.7

unknown

[en] The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the ser...

Affected:
up to 2.9.1.7
Fixed in:
2.9.1.7
Disclosed:
Feb 18, 2025

CVE-2024-13691 on NVD →

Uncode [uncode] < 2.9.1.7

unknown

[en] The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to in...

Affected:
up to 2.9.1.7
Fixed in:
2.9.1.7
Disclosed:
Feb 18, 2025

CVE-2024-13667 on NVD →

Uncode [uncode] < 2.9.1.7

unknown

[en] The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for unauthenticated attackers to read arbitrary files on the server.

Affected:
up to 2.9.1.7
Fixed in:
2.9.1.7
Disclosed:
Feb 18, 2025

CVE-2024-13681 on NVD →

Uncode <= 2.9.1.6 - Unauthenticated Arbitrary File Read in uncode_admin_get_oembed

high

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for unauthenticated attackers to read arbitrary files on the server.

CVSS:
7.5
Affected:
up to 2.9.1.6
Fixed in:
2.9.1.7
Disclosed:
Feb 17, 2025

CVE-2024-13681 on NVD →

Uncode <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary File Read in uncode_recordMedia

medium

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the server.

CVSS:
6.5
Affected:
up to 2.9.1.6
Fixed in:
2.9.1.7
Disclosed:
Feb 17, 2025

CVE-2024-13691 on NVD →

Uncode <= 2.9.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via mle-description

medium

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject...

CVSS:
5.4
Affected:
up to 2.9.1.6
Fixed in:
2.9.1.7
Disclosed:
Feb 17, 2025

CVE-2024-13667 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database