Ultrapress maintains a narrow line of web publishing and blogging platforms including Empowerment, Ultrapress, and Unseen Blog, with a modest but focused vulnerability footprint centered on deserialization of untrusted data. Current exploitation activity, severity distribution, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ultrapress over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7433HIGH The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 via deserialization of untrusted input. This makes it possible | Oct 1, 2024 | 8.8 | 27 | NO | NO |
CVE-2024-7434HIGH The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via deserialization of untrusted input. This makes it possible | Oct 1, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-7432HIGH The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input. This makes it possible | Oct 1, 2024 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ultrapress.
Media articles that mention a CVE ID that affects a product developed by Ultrapress — matched by CVE ID, not by vendor name.