CVEs we hold for Hasthemes
Records whose assigning authority named Hasthemes as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-66605WordPress Swatchly – WooCommerce Variation Swatches for Products plugin <= 1.4.13 - Cross Site Scripting (XSS)…HasThemes Swatchly – WooCommerce Variation Swatches for…
CVE-2025-68533WordPress WC Builder plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerabilityHasThemes WC Builder
CVE-2025-64271WordPress WP Plugin Manager plugin <= 1.4.7 - Cross Site Request Forgery (CSRF) vulnerabilityHasThemes WP Plugin Manager
CVE-2025-2719Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label…hasthemes Swatchly – WooCommerce Variation Swatches for…
CVE-2025-26917WordPress WP Templata plugin <= 1.0.7 - Reflected Cross Site Scripting (XSS) vulnerabilityHasThemes WP Templata
CVE-2025-22801WordPress Free WooCommerce Theme 99fy Extension plugin <= 1.2.8 - Cross Site Scripting (XSS) vulnerabilityHasThemes Free WooCommerce Theme 99fy Extension
CVE-2025-14054WC Builder <= 1.2.0 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'heading_color' Shortcode Attributehasthemes WC Builder – WooCommerce Page Builder for WPBakery
CVE-2024-51682WordPress HT Builder – WordPress Theme Builder for Elementor plugin <= 1.3.0 - Stored Cross Site Scripting (XSS)…HasThemes HT Builder – WordPress Theme Builder for Elementor
CVE-2024-35699WordPress HT Feed plugin <= 1.2.8 - Cross Site Scripting (XSS) vulnerabilityHasThemes HT Feed
CVE-2024-34767WordPress ShopLentor plugin <= 2.8.7 - Cross Site Scripting (XSS) vulnerabilityHasThemes ShopLentor
CVE-2024-29926WordPress WC Builder plugin <= 1.0.18 - Cross Site Scripting (XSS) vulnerabilityHasThemes WC Builder
CVE-2024-29102WordPress Extensions For CF7 plugin <= 3.0.6 - Unauthenticated Cross Site Scripting (XSS) vulnerabilityHasThemes Extensions For CF7
CVE-2024-29094WordPress HT Easy GA4 plugin <= 1.1.7 - Cross Site Scripting (XSS) vulnerabilityHasThemes HT Easy GA4 ( Google Analytics 4 )
CVE-2023-51529WordPress HT Mega Plugin <= 2.3.3 is vulnerable to Cross Site Request Forgery (CSRF)HasThemes HT Mega – Absolute Addons For Elementor
CVE-2023-51372WordPress HashBar – WordPress Notification Bar Plugin <= 1.4.1 is vulnerable to Cross Site Scripting (XSS)HasThemes HashBar – WordPress Notification Bar
CVE-2023-50901WordPress HT Mega Plugin <= 2.3.8 is vulnerable to Cross Site Scripting (XSS)HasThemes HT Mega – Absolute Addons For Elementor
CVE-2023-37999WordPress HT Mega Absolute Addons for Elementor plugin <= 2.2.0 - Unauthenticated Privilege Escalation vulnerabilityHasThemes HT Mega
CVE-2023-23899WordPress Extensions For CF7 Plugin <= 2.0.8 is vulnerable to Cross Site Request Forgery (CSRF)HasThemes Extensions For CF7 (Contact form 7 Database…
CVE-2023-23804WordPress HT Feed Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)HasThemes HT Feed
CVE-2023-23803WordPress JustTables – WooCommerce Product Table Plugin <= 1.4.9 is vulnerable to Cross Site Request Forgery (CSRF)HasThemes JustTables
CVE-2023-23802WordPress HT Easy GA4 ( Google Analytics 4 ) Plugin <= 1.0.6 is vulnerable to Cross Site Request Forgery (CSRF)HasThemes HT Easy GA4 ( Google Analytics 4 )
CVE-2023-23801WordPress Really Simple Google Tag Manager Plugin <= 1.0.6 is vulnerable to Cross Site Request Forgery (CSRF)HasThemes Really Simple Google Tag Manager
CVE-2023-23792WordPress Swatchly – WooCommerce Variation Swatches for Products Plugin <= 1.2.0 is vulnerable to Cross Site Request…HasThemes Swatchly
CVE-2023-23791WordPress HT Menu Plugin <= 1.2.1 is vulnerable to Cross Site Request Forgery (CSRF)HasThemes HT Menu
CVE-2022-47172WordPress WooLentor Plugin <= 2.6.2 is vulnerable to Cross Site Request Forgery (CSRF)HasThemes ShopLentor
CVE-2022-46798WordPress WooLentor Plugin <= 2.5.1 is vulnerable to Cross Site Request Forgery (CSRF)HasThemes ShopLentor
26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.