CVEs we hold for Villatheme
Records whose assigning authority named Villatheme as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-81786WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Control vulnerabilityVillaTheme Thank You Page Customizer for WooCommerce
CVE-2026-81282WordPress Product Variations Swatches for WooCommerce plugin <= 1.1.18 - Cross Site Scripting (XSS) vulnerabilityVillaTheme Product Variations Swatches for WooCommerce
CVE-2026-81277WordPress Suggestion Engine for WooCommerce plugin <= 2.0.11 - SQL Injection vulnerabilityVillaTheme Suggestion Engine for WooCommerce
CVE-2026-57698WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken Authentication vulnerabilityVillaTheme Abandoned Cart Recovery for WooCommerce
CVE-2026-57664WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensitive Data Exposure vulnerabilityVillaTheme Bopo – WooCommerce Product Bundle Builder
CVE-2026-57422WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerabilityVillaTheme Bopo – WooCommerce Product Bundle Builder
CVE-2026-57352WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication…VillaTheme ALD – Dropshipping and Fulfillment for…
CVE-2026-57324WordPress GIFT4U plugin <= 1.0.10 - Broken Access Control vulnerabilityVillaTheme GIFT4U
CVE-2026-40737WordPress COMPE plugin <= 1.1.4 - Insecure Direct Object References (IDOR) vulnerabilityVillaTheme COMPE
CVE-2026-39593WordPress HAPPY plugin <= 1.0.10 - Broken Access Control vulnerabilityVillaTheme HAPPY
CVE-2026-32526WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.10 - Cross Site Scripting (XSS) vulnerabilityVillaTheme Abandoned Cart Recovery for WooCommerce
CVE-2026-28132WordPress WooCommerce Photo Reviews plugin <= 1.4.4 - Content Injection vulnerabilityvillatheme WooCommerce Photo Reviews
CVE-2026-27052WordPress Sales Countdown Timer for WooCommerce and WordPress plugin < 1.1.9 - Local File Inclusion vulnerabilityvillatheme Sales Countdown Timer for WooCommerce and…
CVE-2026-2019Cart All In One For WooCommerce <= 1.1.21 - Authenticated (Administrator+) Code Injection via 'sc_assign_page' Settingvillatheme Cart All In One For WooCommerce
CVE-2026-11778CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parametervillatheme CURCY – Multi Currency for WooCommerce –…
CVE-2025-66528WordPress Thank You Page Customizer for WooCommerce plugin <= 1.1.8 - Broken Access Control vulnerabilityVillaTheme Thank You Page Customizer for WooCommerce
CVE-2025-64200WordPress Email Template Customizer for WooCommerce plugin <= 1.2.17 - Cross Site Scripting (XSS) vulnerabilityVillaTheme Email Template Customizer for WooCommerce
CVE-2025-49372WordPress HAPPY plugin <= 1.0.7 - Remote Code Execution (RCE) vulnerabilityVillaTheme HAPPY
CVE-2025-47570WordPress WooCommerce Photo Reviews plugin <= 1.3.13 - Cross Site Scripting (XSS) vulnerabilityvillatheme WooCommerce Photo Reviews
CVE-2025-47563WordPress CURCY plugin <= 2.3.7 - Arbitrary Shortcode Execution vulnerabilityvillatheme CURCY
CVE-2025-30993WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.7 - Broken Access Control VulnerabilityVillaTheme Thank You Page Customizer for WooCommerce
CVE-2025-22803WordPress Advanced Product Information for WooCommerce plugin <= 1.1.4 - Cross Site Scripting (XSS) vulnerabilityVillaTheme Advanced Product Information for WooCommerce
CVE-2025-14581HAPPY – Helpdesk Support Ticket System <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket…villatheme HAPPY – Helpdesk Support Ticket System
CVE-2025-14541Lucky Wheel Giveaway <= 1.0.22 - Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parametervillatheme Lucky Wheel Giveaway
CVE-2025-14509Lucky Wheel for WooCommerce – Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional…villatheme Lucky Wheel for WooCommerce – Spin a Sale
CVE-2024-8277WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalationvillatheme WooCommerce Photo Reviews Premium
CVE-2024-49288WordPress Email Template Customizer for WooCommerce plugin <= 1.2.9.1 - Cross Site Scripting (XSS) vulnerabilityVillaTheme Email Template Customizer for WooCommerce
CVE-2024-49283WordPress CURCY plugin <= 2.2.3 - Reflected Cross Site Scripting (XSS) vulnerabilityVillaTheme CURCY
CVE-2024-4039Orders Tracking for WooCommerce <= 1.2.10 - Unauthenticated Arbitrary Shortcode Executionvillatheme Orders Tracking for WooCommerce
CVE-2024-1687Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated…villatheme Thank You Page Customizer for WooCommerce –…
CVE-2024-1686Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated…villatheme Thank You Page Customizer for WooCommerce –…
CVE-2024-13487CURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price…villatheme CURCY – Multi Currency for WooCommerce –…
CVE-2024-13320CURCY - WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injectionvillatheme CURCY - WooCommerce Multi Currency - Currency…
CVE-2024-12861W2S – Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Readvillatheme W2S – Migrate WooCommerce to Shopify
CVE-2023-50831WordPress CURCY Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS)VillaTheme CURCY – Multi Currency for WooCommerce
CVE-2023-48778WordPress Product Size Chart For WooCommerce Plugin <= 1.1.5 is vulnerable to Cross Site Request Forgery (CSRF)VillaTheme Product Size Chart For WooCommerce
CVE-2023-30482WordPress WPBulky Plugin < 1.0.10 is vulnerable to Cross Site Scripting (XSS)VillaTheme WPBulky
CVE-2022-46812WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site…VillaTheme Thank You Page Customizer for WooCommerce –…
CVE-2022-46811WordPress ALD Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 1.0.21 - Broken Access Control +…VillaTheme(villatheme.com) ALD – Dropshipping and…
CVE-2022-46810WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site…VillaTheme Thank You Page Customizer for WooCommerce –…
CVE-2022-46806WordPress Cart All In One For WooCommerce Plugin <= 1.1.10 is vulnerable to Cross Site Request Forgery (CSRF)VillaTheme Cart All In One For WooCommerce
CVE-2022-46796WordPress CURCY plugin <= 2.1.25 - Unauthenticated plugin settings change vulnerabilityVillaTheme CURCY
CVE-2022-44634WordPress S2W – Import Shopify to WooCommerce plugin <= 1.1.12 - Auth. Arbitrary File Read vulnerabilityVillaTheme S2W – Import Shopify to WooCommerce (WordPress…
CVE-2022-41623WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data…Villatheme ALD - AliExpress Dropshipping and Fulfillment…
CVE-2021-4395Abandoned Cart Recovery for WooCommerce <= 1.0.4 - Cross-Site Request Forgery Bypassvillatheme Abandoned Cart Recovery for WooCommerce
CVE-2021-4379WooCommerce Multi Currency <= 2.1.17 - Missing Authorizationvillatheme CURCY - WooCommerce Multi Currency - Currency…
CVE-2021-4376WooCommerce Multi Currency <= 2.1.17 - Missing Authorizationvillatheme CURCY – Multi Currency for WooCommerce –…
53 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.