Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Popup Builder MEDIUM 5.3
CVE-2025-62902

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk WP Popup Builder wp-popup-builder allows Retrie…

Fix: after 1.3.6
Fix from $1,600 2025-10-27
Zita CRITICAL 9.8
CVE-2025-52816

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita zita allows P…

Fix: after 1.6.5
Fix from $2,300 2025-06-27
Mega Menu MEDIUM 5.4
CVE-2025-30990

Missing Authorization vulnerability in ThemeHunk ThemeHunk themehunk-megamenu-plus allows Exploiting Incorrectly Configured Access Control Security L…

Fix: after 1.1.2
Fix from $1,600 2025-06-06
Vayu Blocks MEDIUM 6.5
CVE-2025-22644

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Vayu Blocks – Gutenberg Blocks for Wo…

Fix: after 1.4.3
Fix from $1,600 2025-03-27
Big Store MEDIUM 5.4
CVE-2025-30881

Missing Authorization vulnerability in themehunk Big Store big-store allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

Fix: 2.0.9+
Fix from $1,600 2025-03-27
Hunk Companion CRITICAL 9.8
CVE-2024-11972EPSS 54%

The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install a…

Fix: 1.9.0+
Fix from $2,300 2024-12-31
Variation Swatches MEDIUM 5.4
CVE-2023-28688

Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk TH Variation Swatches allows Cross Site Request Forgery.This issue affects TH Variation …

Fix: 1.2.8+
Fix from $1,600 2024-12-09
Wp Popup Builder CRITICAL 9.8
CVE-2024-9061EPSS 52%

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_a…

Fix: 1.3.6+
Fix from $2,300 2024-10-16
Hunk Companion CRITICAL 9.8
CVE-2024-9707EPSS 9%

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-jso…

Fix: 1.8.5+
Fix from $2,300 2024-10-11
Gutenberg Blocks MEDIUM 5.4
CVE-2024-44049

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks.Thi…

Fix: after 1.2.7
Fix from $1,600 2024-09-17
Advance Product Search CRITICAL 9.8
CVE-2022-40218

Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through…

Fix: 1.1.5+
Fix from $2,300 2024-05-08
Contact Form \& Lead Form Elementor Builder MEDIUM 6.1
CVE-2024-3637

The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin through 1.8.9 does not sanitise and escape some of its settings, which …

Fix: after 1.8.9
Fix from $1,600 2024-05-03
Th Advance Product Search CRITICAL 9.8
CVE-2022-38057

Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through…

Fix: 1.2.2+
Fix from $2,300 2024-03-25
Big Store HIGH 8.8
CVE-2023-27431

Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk Big Store theme <= 1.9.3 versions.

Fix: after 1.9.3
Fix from $1,950 2023-11-12
Wp Popup Builder MEDIUM 6.1
CVE-2022-2404

The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Refle…

Fix: 1.2.9+
Fix from $1,600 2022-09-26
Contact Form \& Lead Form Elementor Builder MEDIUM 6.1
CVE-2021-24967

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthe…

Fix: 1.6.4+
Fix from $1,600 2021-12-27