vciy

CVEs we hold for Themehunk

Records whose assigning authority named Themehunk as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-66607WordPress Advance Product Search plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerabilityThemeHunk Advance Product Search
CVE-2026-57405WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerabilitythemehunk Open Shop
CVE-2026-56070WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerabilityThemeHunk Advance Product Search
CVE-2026-32532WordPress Contact Form & Lead Form Elementor Builder plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerabilityThemeHunk Contact Form & Lead Form Elementor Builder
CVE-2026-25438WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Reflected Cross Site Scripting (XSS)…ThemeHunk Gutenberg Blocks
CVE-2026-1454Responsive Contact Form Builder & Lead Generation Plugin <= 2.0.1 - Unauthenticated Stored Cross-Site Scriptingthemehunk Lead Form Builder & Contact Form
CVE-2026-14250Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' Parameterthemehunk TH Login Registration
CVE-2026-12753Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and…themehunk Advance Product Search- Voice & Ajax Search for…
CVE-2025-9378Vayu Blocks <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Block Attributesthemehunk Vayu Blocks – Website Builder for the Block Editor
CVE-2025-69344WordPress Oneline Lite theme <= 6.6 - Broken Access Control vulnerabilitythemehunk Oneline Lite
CVE-2025-68046WordPress Contact Form & Lead Form Elementor Builder plugin <= 2.0.1 - Sensitive Data Exposure vulnerabilityThemeHunk Contact Form & Lead Form Elementor Builder
CVE-2025-62902WordPress WP Popup Builder plugin <= 1.3.8 - Sensitive Data Exposure vulnerabilityThemeHunk WP Popup Builder
CVE-2025-52816WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerabilitythemehunk Zita
CVE-2025-4420Vayu Blocks <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via…themehunk Vayu Blocks – Website Builder for the Block Editor
CVE-2025-30990WordPress ThemeHunk plugin <= 1.2.0 - Broken Access Control vulnerabilityThemeHunk
CVE-2025-30881WordPress Big Store theme <= 2.0.8 - Broken Access Control vulnerabilitythemehunk Big Store
CVE-2025-2568Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated…themehunk Vayu Blocks – Gutenberg Blocks for WordPress &…
CVE-2025-22644WordPress Vayu Blocks – Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) vulnerabilityThemeHunk Vayu Blocks – Gutenberg Blocks for WordPress &…
CVE-2025-12040Wishlist for WooCommerce <= 1.1.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulationthemehunk Wishlist for WooCommerce
CVE-2024-9707Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activationthemehunk Hunk Companion
CVE-2024-9061WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution…themehunk WP Popup Builder – Popup Forms and Marketing Lead…
CVE-2024-8434Easy Mega Menu Plugin for WordPress – ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+)…ThemeHunk
CVE-2024-8433Easy Mega Menu Plugin for WordPress – ThemeHunk <= 1.1.0 - Authenticated (Subscriber+) Stored Cross-Site ScriptingThemeHunk
CVE-2024-54369WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerabilityThemeHunk Zita Site Builder
CVE-2024-44049WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Authenticated Cross Site Scripting (XSS)…ThemeHunk Gutenberg Blocks
CVE-2024-4261Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.1 - Authenticated (Subscriber+) Arbitrary Shortcode…themehunk Lead Form Builder & Contact Form
CVE-2024-1416Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Missing Authorizationthemehunk Lead Form Builder & Contact Form
CVE-2024-1415Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Cross-Site Request Forgerythemehunk Lead Form Builder & Contact Form
CVE-2024-13511Variation Swatches for WooCommerce 1.0.8 - 1.3.2 - Cross-Site Request Forgery to Plugin Settings Resetthemehunk Variation Swatches for WooCommerce
CVE-2024-10674Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activationthemehunk Th Shop Mania
CVE-2024-10673Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activationthemehunk Top Store
CVE-2024-10124Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated…themehunk Vayu Blocks – Website Builder for the Block Editor
CVE-2023-28688WordPress TH Variation Swatches plugin <= 1.2.7 - Cross-Site Request Forgery (CSRF) vulnerabilityThemeHunk TH Variation Swatches
CVE-2023-27431WordPress Big Store Theme <= 1.9.3 is vulnerable to Cross Site Request Forgery (CSRF)ThemeHunk Big Store
CVE-2023-25969WordPress Contact Form & Lead Form Elementor Builder plugin <= 1.8.4 - Broken Access Control vulnerabilityThemeHunk Contact Form & Lead Form Elementor Builder
CVE-2022-40218WordPress TH Advance Product Search plugin <= 1.1.4 - Unauthenticated Plugin Settings Change vulnerabilityThemeHunk Advance WordPress Search Plugin
CVE-2022-38057WordPress TH Advance Product Search plugin <= 1.2.1 - Unauthenticated Plugin Settings Reset vulnerabilityThemeHunk Advance WordPress Search Plugin

37 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.