Posthemes develops a focused set of WordPress plugins including Posrotatorimg and Posstaticblocks, which extend site functionality through content rotation and block management. The vulnerability profile centers on SQL injection weaknesses in input handling within these plugins, reflecting the application-layer risks inherent to server-side scripting and database interaction. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Posthemes over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45379CRITICAL In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can perform SQL injection. | Oct 19, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-30189CRITICAL Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook(). | May 16, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Posthemes.
Media articles that mention a CVE ID that affects a product developed by Posthemes — matched by CVE ID, not by vendor name.