
CVE-2023-46145 – WordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerability
https://notcve.org/view.php?id=CVE-2023-46145
17 Oct 2023 — Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5. La vulnerabilidad de gestión de privilegios incorrecta en Themify Themify Ultra permite la escalada de privilegios. Este problema afecta a Themify Ultra: desde n/a hasta 7.3.5. The themify-ultra theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.5. This makes it possible for low-level attackers with subscri... • https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-authenticated-privilege-escalation-vulnerability?_s_id=cve • CWE-269: Improper Privilege Management •

CVE-2023-46146 – WordPress Themify Ultra theme <= 7.3.5 - Multiple Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2023-46146
17 Oct 2023 — Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. Vulnerabilidad de autorización faltante en Themify Themify Ultra. Este problema afecta a Themify Ultra: desde n/a hasta 7.3.5. The Themify Ultra theme for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on one of its functions in versions up to, and including, 7.3.5. This makes it possible for authenticated attackers, with subscriber-level acce... • https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-multiple-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •

CVE-2023-46147 – WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to PHP Object Injection
https://notcve.org/view.php?id=CVE-2023-46147
17 Oct 2023 — Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. Vulnerabilidad de deserialización de datos no confiables en Themify Themify Ultra. Este problema afecta a Themify Ultra: desde n/a hasta 7.3.5. The themify-ultra theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.3.5 via deserialization of untrusted input. This makes it possible for authenticated attackers with subscriber access and... • https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-authenticated-php-object-injection-vulnerability?_s_id=cve • CWE-502: Deserialization of Untrusted Data •

CVE-2023-46148 – WordPress Themify Ultra theme <= 7.3.5 - Authenticated Arbitrary Settings Change vulnerability
https://notcve.org/view.php?id=CVE-2023-46148
17 Oct 2023 — Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. Vulnerabilidad de autorización faltante en Themify Themify Ultra. Este problema afecta a Themify Ultra: desde n/a hasta 7.3.5. The themify-ultra theme for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on an unknown function in all versions up to, and including, 7.3.5. This makes it possible for authenticated attackers with sub... • https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-authenticated-arbitrary-settings-change-vulnerability?_s_id=cve • CWE-862: Missing Authorization •