Pricing
Case studies
Login
Start trial
Enfold
Kriesi
Developer
N/A
Latest version
N/A
Downloads
N/A
Last updated
WordPress Theme
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
9 fixed
4 Mitigation rules
Cross Site Scripting (XSS) vulnerability
<= 7.1.2
Oct 21, 2025
Authenticated (Subscriber+) Server-Side Request Forgery via attachment_id vulnerability
<= 6.0.9
Feb 24, 2025
Missing Authorization to Sensitive Information Disclosure in avia-export-class.php vulnerability
<= 6.0.9
Feb 24, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via wrapper_class and class Parameters vulnerability
<= 6.0.3
Aug 30, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 5.6.9
Jun 20, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 5.6.4
Nov 23, 2023
Reflected Cross-Site Scripting (XSS) vulnerability
<= 4.8.3
Sep 6, 2021
Rewrite Portfolio Permalink Structure & Information Disclosure
<= 4.2
Jan 30, 2018
Unspecified Vulnerability
<= 3.0.0
Oct 2, 2014