VendorsKriesienfoldany version
Vulnerabilities

Kriesi Enfold any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2014-7297
Unspecified vulnerability in the folder framework in the Enfold theme before 3.0.1 for WordPress has unknown impact and attack vectors.
Published 2014-10-13 · Modified
10.0EPSS 0.021
CVE-2023-38400
WordPress Enfold Theme <= 5.6.4 is vulnerable to Cross Site Scripting (XSS)
Published 2023-11-30 · Modified
7.1EPSS 0.004
CVE-2024-37199
WordPress Enfold theme <= 5.6.9 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-07-22 · Modified
7.1EPSS 0.003
CVE-2024-5061
Enfold <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wrapper_class and class Parameters
Published 2024-08-30 · Modified
6.4EPSS 0.003
CVE-2024-13695
Enfold <= 6.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery via attachment_id
Published 2025-02-25 · Analyzed
6.4EPSS 0.003
CVE-2021-24719
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
Published 2021-10-11 · Modified
6.11 PoCEPSS 0.030
CVE-2024-13693
Enfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.php
Published 2025-02-25 · Analyzed
5.3EPSS 0.003