Wpattire develops WordPress theme and block components, with observed vulnerabilities concentrating in its Attire and Attire Blocks products around untrusted deserialization and missing authorization controls. These weakness classes reflect risks common to WordPress plugins and themes that extend core functionality without robust input validation or capability-checking mechanisms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpattire over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7435HIGH The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This makes it possible for | Aug 31, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-4088MEDIUM The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable_fe_as | Jun 5, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpattire.
Media articles that mention a CVE ID that affects a product developed by Wpattire — matched by CVE ID, not by vendor name.