CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Themehunk Remove filter Clear all
CVE-2026-66607 HIGH

WordPress Advance Product Search plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.25% Aug 20, 2026
CVE-2026-12753 HIGH

Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter

CVSS 7.5 EPSS 0.51% Jul 16, 2026
CVE-2026-57405 HIGH

WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability

CVSS 7.1 EPSS 0.32% Jul 13, 2026
CVE-2026-14250 MEDIUM

Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' Parameter

CVSS 6.3 EPSS 0.37% Jul 8, 2026
CVE-2026-56070 CRITICAL

WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerability

CVSS 9.3 EPSS 0.40% Jun 26, 2026
CVE-2023-25969 MEDIUM

WordPress Contact Form & Lead Form Elementor Builder plugin <= 1.8.4 - Broken Access Control vulnerability

CVSS 5.4 EPSS 0.18% Jun 11, 2026
CVE-2026-32532 HIGH

WordPress Contact Form & Lead Form Elementor Builder plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.25% Mar 25, 2026
CVE-2026-25438 HIGH

WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Reflected Cross Site Scripting (XSS) vulnerability

CVSS 7.1 EPSS 0.25% Mar 19, 2026
CVE-2026-1454 HIGH

Responsive Contact Form Builder & Lead Generation Plugin <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting

CVSS 7.2 EPSS 0.24% Mar 11, 2026
CVE-2025-68046 MEDIUM

WordPress Contact Form & Lead Form Elementor Builder plugin <= 2.0.1 - Sensitive Data Exposure vulnerability

CVSS 6.5 EPSS 0.41% Jan 22, 2026
CVE-2025-69344 MEDIUM

WordPress Oneline Lite theme <= 6.6 - Broken Access Control vulnerability

CVSS 4.3 EPSS 0.18% Jan 7, 2026
CVE-2025-12040 MEDIUM

Wishlist for WooCommerce <= 1.1.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation

CVSS 6.5 EPSS 0.24% Nov 25, 2025
CVE-2025-62902 MEDIUM

WordPress WP Popup Builder plugin <= 1.3.8 - Sensitive Data Exposure vulnerability

CVSS 5.3 EPSS 0.31% Oct 27, 2025
CVE-2025-9378 MEDIUM

Vayu Blocks <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Block Attributes

CVSS 6.4 EPSS 0.24% Sep 3, 2025
CVE-2025-52816 CRITICAL

WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerability

CVSS 9.8 EPSS 0.52% Jun 27, 2025
CVE-2025-30990 MEDIUM

WordPress ThemeHunk plugin <= 1.2.0 - Broken Access Control vulnerability

CVSS 5.4 EPSS 0.25% Jun 6, 2025
CVE-2025-4420 MEDIUM

Vayu Blocks <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via containerWidth Parameter

CVSS 6.4 EPSS 0.28% Jun 3, 2025
CVE-2024-10475 MEDIUM

Lead Form Builder < 1.9.8 - Admin+ Stored XSS

CVSS 4.8 EPSS 0.31% May 15, 2025
CVE-2025-2568 MEDIUM

Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary Options Update

CVSS 5.3 EPSS 0.38% Apr 8, 2025
CVE-2025-22644 MEDIUM

WordPress Vayu Blocks – Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) vulnerability

CVSS 6.5 EPSS 0.25% Mar 27, 2025
CVE-2025-30881 MEDIUM

WordPress Big Store theme <= 2.0.8 - Broken Access Control vulnerability

CVSS 5.4 EPSS 0.36% Mar 27, 2025
CVE-2024-13511 MEDIUM

Variation Swatches for WooCommerce 1.0.8 - 1.3.2 - Cross-Site Request Forgery to Plugin Settings Reset

CVSS 4.3 EPSS 0.19% Jan 23, 2025
CVE-2024-11972 CRITICAL

Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation

CVSS 9.8 EPSS 54.47% Dec 31, 2024
CVE-2024-54369 CRITICAL

WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability

CVSS 9.1 EPSS 1.63% Dec 16, 2024
CVE-2024-10124 CRITICAL

Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

CVSS 9.8 EPSS 32.73% Dec 12, 2024

Showing 1 to 25 CVEs · page 1 (more available)