Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Themefic — Vulnerabilities & Security Advisories 50

Browse all 50 CVE security advisories affecting Themefic. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Themefic operates as a provider of WordPress themes and plugins, primarily targeting small to medium-sized businesses seeking pre-designed web templates. Security audits reveal a concerning pattern of thirty-six recorded Common Vulnerabilities and Exposures (CVEs), indicating systemic weaknesses in code quality and input validation. Historically, the platform has been susceptible to critical vulnerability classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection. These flaws often stem from insufficient sanitization of user inputs and improper handling of file uploads, allowing attackers to execute arbitrary commands or steal session data. Additionally, instances of privilege escalation have been documented, enabling unauthorized users to gain administrative access. While specific major incidents involving widespread data breaches are not prominently detailed in public records, the high volume of CVEs suggests a persistent need for rigorous security patching and code review processes to mitigate ongoing risks for dependent websites.

CVE ID Title CVSS Severity Published
CVE-2026-15948 Hydra Booking <= 1.2.2 - Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter — Hydra Booking — Appointment Scheduling & Booking Calendar CWE-79 6.4 Medium 2026-08-15
CVE-2026-28188 WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability — Hydra Booking CWE-862 7.3 High 2026-08-13
CVE-2026-28186 WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerability — Travelfic Toolkit CWE-862 8.1 High 2026-08-13
CVE-2026-27999 WordPress Tourfic plugin <= 2.23.1 - Broken Access Control vulnerability — Tourfic CWE-862 6.5 Medium 2026-08-13
CVE-2026-12801 Ultra Addons for Contact Form 7 <= 3.5.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes — Ultra Addons for Contact Form 7 CWE-79 6.4 Medium 2026-08-07
CVE-2026-65439 WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scripting (XSS) vulnerability — Ultimate Addons for Contact Form 7 CWE-79 7.1 High 2026-07-27
CVE-2026-57395 WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability — Tourfic CWE-862 6.5 Medium 2026-07-13
CVE-2026-57392 WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability — Tourfic CWE-862 6.5 Medium 2026-07-13
CVE-2026-57388 WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerability — Hydra Booking CWE-79 7.1 High 2026-07-13
CVE-2026-12433 Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter — Hydra Booking — Appointment Scheduling & Booking Calendar CWE-639 4.3 Medium 2026-07-09
CVE-2026-56064 WordPress Tourfic plugin <= 2.22.5 - SQL Injection vulnerability — Tourfic CWE-89 8.5 High 2026-06-26
CVE-2026-12937 Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter — Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin CWE-89 7.5 High 2026-06-25
CVE-2026-39594 WordPress Ultra Addons for WPForms plugin <= 1.0.11 - Broken Access Control vulnerability — Ultra Addons for WPForms CWE-862 6.4 Medium 2026-06-15
CVE-2026-42675 WordPress Hydra Booking plugin <= 1.1.41 - Broken Access Control vulnerability — Hydra Booking CWE-862 7.3 High 2026-06-01
CVE-2026-39571 WordPress Instantio plugin <= 3.3.30 - Sensitive Data Exposure vulnerability — Instantio CWE-497 5.3 Medium 2026-04-08
CVE-2026-39543 WordPress Tourfic plugin <= 2.21.4 - Broken Access Control vulnerability — Tourfic CWE-862 5.3 Medium 2026-04-08
CVE-2026-39541 WordPress Hydra Booking plugin <= 1.1.38 - Cross Site Scripting (XSS) vulnerability — Hydra Booking CWE-79 5.9 Medium 2026-04-08
CVE-2026-32460 WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.36 - Cross Site Scripting (XSS) vulnerability — Ultimate Addons for Contact Form 7 CWE-79 6.5 Medium 2026-03-13
CVE-2026-24940 WordPress Travelfic Toolkit plugin <= 1.3.3 - Broken Access Control vulnerability — Travelfic Toolkit CWE-862 4.3 Medium 2026-02-03
CVE-2026-24945 WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.34 - Broken Access Control vulnerability — Ultimate Addons for Contact Form 7 CWE-862 5.3 Medium 2026-02-03
CVE-2025-68027 WordPress Hydra Booking plugin <= 1.1.32 - Privilege Escalation vulnerability — Hydra Booking CWE-266 7.3 High 2026-01-22
CVE-2025-68055 WordPress Hydra Booking plugin <= 1.1.32 - SQL Injection vulnerability — Hydra Booking CWE-89 8.5 High 2025-12-16
CVE-2025-14356 Ultra Addons for Contact Form 7 <= 3.5.33 - Missing Authorization to Authenticated (Subscriber+) to Generate Form Submission PDF — Ultra Addons for Contact Form 7 CWE-639 4.3 Medium 2025-12-12
CVE-2025-12788 Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass — Hydra Booking — Appointment Scheduling & Booking Calendar CWE-602 5.3 Medium 2025-11-11
CVE-2025-12787 Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation — Hydra Booking — Appointment Scheduling & Booking Calendar CWE-330 5.3 Medium 2025-11-11
CVE-2025-49377 WordPress Hydra Booking plugin <= 1.1.9 - Broken Access Control vulnerability — Hydra Booking CWE-862 6.3 Medium 2025-10-22
CVE-2025-49378 WordPress Hydra Booking plugin <= 1.1.10 - SQL Injection vulnerability — Hydra Booking CWE-89 8.5 High 2025-10-22
CVE-2024-8860 Tourfic <= 2.14.5 - Missing Authorization in Multiple Functions — Tourfic – Travel Booking, Hotel Booking & Car Rental WordPress Plugin CWE-862 4.3 Medium 2025-08-26
CVE-2025-7689 Hydra Booking 1.1.0 - 1.1.18 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via tfhb_reset_password_callback Function — Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings CWE-862 8.8 High 2025-07-29
CVE-2025-6756 Ultra Addons for Contact Form 7 <= 3.5.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via UACF7_CUSTOM_FIELDS Shortcode — Ultra Addons for Contact Form 7 CWE-79 6.4 Medium 2025-07-01

This page lists every published CVE security advisory associated with Themefic. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.