vciy

CVEs we hold for Themeisle

Records whose assigning authority named Themeisle as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8976RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation…themeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2026-8689Visualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Authorization to Authenticated (Subscriber+)…themeisle Visualizer: Tables and Charts Manager for…
CVE-2026-85198MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Paththemeisle MPG – Multiple Page Generator, Bulk Landing Pages…
CVE-2026-66437WordPress Feedzy plugin <= 5.2.4 - Server Side Request Forgery (SSRF) vulnerabilityThemeisle Feedzy
CVE-2026-65563WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerabilityThemeIsle
CVE-2026-65537WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control…Themeisle Cyr to Lat reloaded – transliteration of links…
CVE-2026-65526WordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerabilityThemeisle Visualizer
CVE-2026-61970WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerabilityThemeisle Auto Featured Image (Auto Post Thumbnail)
CVE-2026-61960WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerabilityThemeisle WP Full Stripe Free
CVE-2026-57618WordPress Neve PRO theme <= 3.1.2 - Cross Site Scripting (XSS) vulnerabilityThemeisle Neve PRO
CVE-2026-56050WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerabilityThemeisle PPOM for WooCommerce
CVE-2026-4945Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification Bypassthemeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2026-42749WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerabilityThemeisle Disable Comments for Any Post Types (Remove…
CVE-2026-42378WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerabilityThemeisle WP Full Stripe Free
CVE-2026-39507WordPress Social Slider Feed plugin <= 2.3.2 - Cross Site Scripting (XSS) vulnerabilityThemeisle Social Slider Feed
CVE-2026-2892Otter Blocks <= 3.1.4 - Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookiethemeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2026-25366WordPress Woody ad snippets plugin <= 2.7.1 - Remote Code Execution (RCE) vulnerabilityThemeisle Woody ad snippets
CVE-2026-24573WordPress Visualizer plugin < 4.0.0 - Cross Site Scripting (XSS) vulnerabilityThemeisle Visualizer
CVE-2026-2410Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Updatethemeisle Disable Admin Notices – Hide Dashboard…
CVE-2026-23970WordPress Redirection for Contact Form 7 plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerabilityThemeisle Redirection for Contact Form 7
CVE-2026-1755Menu Icons by ThemeIsle <= 0.13.20 - Authenticated (Author+) Stored Cross-Site ScriptingThemeIsle
CVE-2026-15653Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameterthemeisle Visualizer – Tables & Charts Manager with…
CVE-2026-13468Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via…themeisle Visualizer – Tables & Charts Manager with…
CVE-2026-13252RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attributethemeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2026-1319Robin Image Optimizer <= 2.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Alternative Text Fieldthemeisle Robin Image Optimizer – Unlimited Image…
CVE-2026-12432Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via…themeisle Stripe Payment Forms by WP Full Pay – Accept…
CVE-2026-11358Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 - Authenticated…themeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2025-9562Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcodethemeisle Redirection for Contact Form 7
CVE-2025-9322Stripe Payment Forms <= 8.3.1 - Unauthenticated SQL Injectionthemeisle Stripe Payment Forms by WP Full Pay – Accept…
CVE-2025-8289Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection via PHAR Deserializationthemeisle Redirection for Contact Form 7
CVE-2025-8145Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injectionthemeisle Redirection for Contact Form 7
CVE-2025-8141Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated Arbitrary File Deletionthemeisle Redirection for Contact Form 7
CVE-2025-66069WordPress PPOM for WooCommerce plugin <= 33.0.16 - Broken Access Control vulnerabilityThemeisle PPOM for WooCommerce
CVE-2025-58789WordPress WP Full Stripe Free Plugin <= 8.2.5 - SQL Injection VulnerabilityThemeisle WP Full Stripe Free
CVE-2025-58593WordPress Orbit Fox by ThemeIsle Plugin <= 3.0.0 - Cross Site Scripting (XSS) VulnerabilityThemeIsle
CVE-2025-55715WordPress Otter - Gutenberg Block Plugin <= 3.1.0 - Sensitive Data Exposure VulnerabilityThemeisle Otter - Gutenberg Block
CVE-2025-53986WordPress Hestia theme <= 3.2.10 - Broken Access Control Vulnerabilitythemeisle Hestia
CVE-2025-53254WordPress Cyrlitera plugin <= 1.3.0 - Cross Site Request Forgery (CSRF) vulnerabilityThemeisle Cyrlitera
CVE-2025-53209WordPress Masteriyo LMS PRO plugin <= 2.20.0 - Privilege Escalation VulnerabilityThemeisle Masteriyo LMS PRO
CVE-2025-24668WordPress PPOM for WooCommerce plugin <= 33.0.8 - Cross Site Scripting (XSS) vulnerabilityThemeisle PPOM for WooCommerce
CVE-2025-24666WordPress Hyve Lite plugin <= 1.2.2 - Cross Site Scripting (XSS) vulnerabilityThemeisle AI Chatbot for WordPress – Hyve Lite
CVE-2025-22659WordPress Orbit Fox by ThemeIsle plugin <= 2.10.44 - Cross Site Scripting (XSS) vulnerabilityThemeIsle
CVE-2025-14800Redirection for Contact Form 7 <= 3.2.7 - Unauthenticated Arbitrary File Copy via move_file_to_uploadthemeisle Redirection for Contact Form 7
CVE-2025-13794Auto Featured Image <= 4.2.1 - Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modificationthemeisle Auto Featured Image (Auto Post Thumbnail)
CVE-2025-12483Visualizer: Tables and Charts Manager for WordPress <= 3.11.12 - Authenticated (Contributor+) SQL Injectionthemeisle Visualizer: Tables and Charts Manager for…
CVE-2025-12045Orbit Fox Companion <= 3.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post Taxonomythemeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2025-11691PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated SQL Injectionthemeisle PPOM – Product Addons & Custom Fields for…
CVE-2025-11467RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated…themeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2025-11391PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated Arbitrary File Uploadthemeisle PPOM – Product Addons & Custom Fields for…
CVE-2025-11128Feedzy RSS Feeds Lite <= 5.1.0 - Authenticated (Subscriber+) Server-Side Request Forgerythemeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2025-1065Visualizer: Tables and Charts Manager for WordPress <= 3.11.8 - Authenticated (Contributor+) Stored Cross-Site…themeisle Visualizer: Tables and Charts Manager for…
CVE-2025-0311Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widgetthemeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2024-7778Orbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploadthemeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2024-7424Multiple Page Generator Plugin – MPG <= 4.0.1 - Missing Authorizationthemeisle Multiple Page Generator Plugin – MPG
CVE-2024-52420WordPress Disable Admin Notices individually plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulnerabilityThemeisle Disable Admin Notices individually
CVE-2024-51671WordPress Otter Blocks plugin <= 3.0.3 - Broken Access Control vulnerabilityThemeisle Otter - Gutenberg Block
CVE-2024-47325WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.7 - SQL Injection vulnerabilityThemeisle MPG
CVE-2024-4635Menu Icons by ThemeIsle <= 0.13.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG UploadThemeIsle
CVE-2024-3962Product Addons & Fields for WooCommerce <= 32.0.18 - Unauthenticated Arbitrary File Upload via ppom_upload_filethemeisle PPOM – Product Addons & Custom Fields for…
CVE-2024-3750Visualizer: Tables and Charts Manager for WordPress <= 3.10.15 - Missing Authorization to Arbitrary SQL Executionthemeisle Visualizer: Tables and Charts Manager for…
CVE-2024-37467WordPress Hestia theme <= 3.1.2 - Cross Site Request Forgery (CSRF) vulnerabilitythemeisle Hestia
CVE-2024-3725Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.9 - Authenticated (Contributor+) Stored…themeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2024-35736WordPress Visualizer plugin <= 3.11.1 - SQL Injection vulnerabilityThemeisle Visualizer
CVE-2024-35728WordPress Product Addons & Fields for WooCommerce plugin <= 32.0.20 - Content Injection vulnerabilityThemeisle PPOM for WooCommerce
CVE-2024-35682WordPress Otter Blocks PRO plugin <= 2.6.11 - Authenticated Sensitive Data Exposure vulnerabilityThemeisle Otter Blocks PRO
CVE-2024-3344Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited…themeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2024-3343Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored…themeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2024-31301WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) vulnerabilityThemeisle Multiple Page Generator Plugin – MPG
CVE-2024-3105Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code…themeisle Woody Code Snippets – Insert PHP, CSS, JS, and…
CVE-2024-30235WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Broken Access Control vulnerabilityThemeisle Multiple Page Generator Plugin – MPG
CVE-2024-2841Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 - Authenticated (Contributor+) Stored…themeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2024-27958WordPress Visualizer plugin <= 3.10.5 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeisle Visualizer
CVE-2024-27951WordPress Multiple Page Generator Plugin <= 3.4.0 - Auth. Remote Code Execution (RCE) vulnerabilityThemeisle Multiple Page Generator Plugin – MPG
CVE-2024-2484Orbit Fox by ThemeIsle <= 2.10.34 - Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type…themeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2024-2226Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored…themeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2024-2126Orbit Fox by ThemeIsle <= 2.10.32 - Authenticated (Contributor+) Stored Cross-Site Scripiting via Registration Form…themeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2024-1499Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scriptingthemeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2024-1497Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via form widget…themeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2024-1323Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scriptingthemeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2024-13183Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag Parameterthemeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2024-1318RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publicationthemeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2024-1317RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injectionthemeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2024-1162Orbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request Forgerythemeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2024-11219Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to…themeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2024-1092RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing…themeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2024-10705Multiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrlthemeisle Multiple Page Generator Plugin – MPG
CVE-2024-10672Multiple Page Generator Plugin – MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File Deletionthemeisle Multiple Page Generator Plugin – MPG
CVE-2024-1047ThemeIsle SDK <= Various Versions - Missing Authorizationthemeisle PPOM – Product Addons & Custom Fields for…
CVE-2024-10367Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 - Authenticated (Author+) Stored…themeisle Otter Blocks – Gutenberg Blocks, Page Builder for…
CVE-2024-0508Orbit Fox by ThemeIsle <= 2.10.27 - Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor…themeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2023-7073Auto Featured Image (Auto Post Thumbnail) <= 4.1.7 - Authenticated (Author+) Server-Side Request Forgerythemeisle Auto Featured Image (Auto Post Thumbnail)
CVE-2023-7019LightStart – Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 - Missing Authorizationthemeisle LightStart – Maintenance Mode, Coming Soon and…
CVE-2023-6877RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated…themeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2023-6805RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 -…themeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2023-6801RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated…themeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2023-6798RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing…themeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2023-6781Orbit Fox Companion <= 2.10.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via custom fieldsthemeisle Orbit Fox: Duplicate Page, Menu Icons, SVG…
CVE-2023-4887Google Maps Plugin by Intergeo <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodethemeisle Google Maps Plugin by Intergeo
CVE-2023-47529WordPress Cloud Templates & Patterns collection Plugin <= 1.2.2 is vulnerable to Sensitive Data ExposureThemeIsle Cloud Templates & Patterns collection
CVE-2023-39920WordPress Redirection for Contact Form 7 plugin <= 2.9.2 - Broken Access Control vulnerabilityThemeisle Redirection for Contact Form 7
CVE-2023-33927WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.19 is vulnerable to SQL InjectionThemeisle Multiple Page Generator Plugin – MPG
CVE-2023-2608Multiple Page Generator Plugin <= 3.3.17 - Cross-Site Request Forgery to SQL Injectionthemeisle Multiple Page Generator Plugin – MPG
CVE-2023-2607Multiple Page Generator Plugin <= 3.3.17 - Authenticated (Administrator+) SQL Injectionthemeisle Multiple Page Generator Plugin – MPG
CVE-2023-23708WordPress Visualizer Plugin <= 3.9.4 is vulnerable to Cross Site Scripting (XSS)Themeisle Visualizer: Tables and Charts Manager for…
CVE-2022-47143WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF)Themeisle Multiple Page Generator Plugin – MPG
CVE-2022-46848WordPress Visualizer Plugin <= 3.9.1 is vulnerable to Cross Site Scripting (XSS)Themeisle Visualizer: Tables and Charts Manager for…
CVE-2022-2444Visualizer: Tables and Charts Manager for WordPress <= 3.7.9 - Authenticated (Contributor+) PHAR Deserializationthemeisle Visualizer: Tables and Charts Manager for…
CVE-2020-36759Woody code snippets <= 2.3.9 - Cross-Site Request Forgery Bypassthemeisle Woody Code Snippets – Insert PHP, CSS, JS, and…
CVE-2020-36758RSS Aggregator by Feedzy <= 3.4.2 - Cross-Site Request Forgery Bypassthemeisle RSS Aggregator by Feedzy – Feed to Post…
CVE-2017-20251WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST APIThemeisle Woody Code Snippets

110 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.