theme

Vithy Vulnerabilities

10 known security issues reported for the Vithy WordPress theme. Most recent disclosed Aug 1, 2014.

1 critical 1 medium

Running Vithy on your site? Check whether your installed version is affected.

Scan your site free

Vithy [vithy] < 1.1 (closed)

unknown

This WordPress theme is prone to a shell upload vulnerability. Update the theme.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Vithy [vithy] < 1.1 (closed)

unknown

Because of this vulnerabilitity, attackers can obtain the installation path via a direct request to various files. Update the theme.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Vithy [vithy] < 1.1 (closed)

unknown

WordPress ColdFusion theme is prone to an arbitrary file upload vulnerability. It allows an attacker to upload arbitrary files to the affected computer. Update the theme.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Vithy (All Versions) - Arbitrary File Upload

critical

The Vithy theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uploadify.php file in all known versions. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVSS:
9.8
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Mar 22, 2014

Vithy [vithy] < 100 (unfixed + closed)

unknown

The Vithy theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the uploadify.php file in all known versions. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Mar 22, 2014

Vithy (Unknown Versions) - Full Path Disclosure

medium

The Vithy theme for WordPress is vulnerable to Sensitive Data Exposure in all versions via the index.php file. This can allow unauthenticated attackers to extract sensitive data including the full path of the WordPress installation.

CVSS:
5.3
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Dec 4, 2012

Vithy [vithy] < 100 (unfixed)

unknown

The Vithy theme for WordPress is vulnerable to Sensitive Data Exposure in all versions via the index.php file. This can allow unauthenticated attackers to extract sensitive data including the full path of the WordPress installation.

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Dec 4, 2012

Vithy [vithy] < 100 (unfixed)

unknown

The vithy WordPress theme was affected by an Arbitrary File Upload security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Vithy [vithy] < 100 (unfixed)

unknown

The vithy WordPress theme was affected by a Full Path Disclosure security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Vithy [vithy] < 100 (unfixed)

unknown

The vithy WordPress theme was affected by a Custom Background Shell Upload security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database