Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Villatheme — Vulnerabilities & Security Advisories 48

Browse all 48 CVE security advisories affecting Villatheme. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Villatheme operates as a provider of WordPress themes and plugins, primarily targeting niche markets such as gaming, streaming, and multimedia content. Security audits reveal a concerning pattern of forty documented Common Vulnerabilities and Exposures (CVEs), indicating systemic weaknesses in the development lifecycle. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper sanitization of user-supplied data. Additionally, instances of broken access control and privilege escalation have been recorded, allowing unauthorized users to manipulate administrative functions. These flaws frequently arise from outdated codebases and a lack of rigorous security testing before deployment. The high volume of CVEs suggests that Villatheme products pose significant risks to website integrity, potentially enabling attackers to compromise entire server environments through simple exploitation of these known entry points.

CVE ID Title CVSS Severity Published
CVE-2026-57698 WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken Authentication vulnerability — Abandoned Cart Recovery for WooCommerce CWE-288 6.5 Medium 2026-07-13
CVE-2026-57422 WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability — Bopo – WooCommerce Product Bundle Builder CWE-79 7.1 High 2026-07-13
CVE-2026-11778 CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter — CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x CWE-94 5.4 Medium 2026-07-03
CVE-2026-57352 WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication vulnerability — ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce CWE-1390 4.8 Medium 2026-07-02
CVE-2026-57664 WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensitive Data Exposure vulnerability — Bopo – WooCommerce Product Bundle Builder CWE-497 4.3 Medium 2026-06-26
CVE-2026-57324 WordPress GIFT4U plugin <= 1.0.10 - Broken Access Control vulnerability — GIFT4U CWE-862 6.5 Medium 2026-06-26
CVE-2026-54809 WordPress GIFT4U plugin <= 1.0.10 - SQL Injection vulnerability — GIFT4U CWE-89 9.3 Critical 2026-06-17
CVE-2026-39593 WordPress HAPPY plugin <= 1.0.10 - Broken Access Control vulnerability — HAPPY CWE-862 6.5 Medium 2026-05-21
CVE-2026-40737 WordPress COMPE plugin <= 1.1.4 - Insecure Direct Object References (IDOR) vulnerability — COMPE CWE-639 5.3 Medium 2026-04-15
CVE-2026-32526 WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.10 - Cross Site Scripting (XSS) vulnerability — Abandoned Cart Recovery for WooCommerce CWE-79 7.1 High 2026-03-25
CVE-2026-28132 WordPress WooCommerce Photo Reviews plugin <= 1.4.4 - Content Injection vulnerability — WooCommerce Photo Reviews CWE-80 5.3 Medium 2026-02-26
CVE-2025-67977 WordPress HAPPY plugin <= 1.0.8 - Broken Access Control vulnerability — HAPPY CWE-862 8.2 High 2026-02-20
CVE-2026-27052 WordPress Sales Countdown Timer for WooCommerce and WordPress plugin < 1.1.9 - Local File Inclusion vulnerability — Sales Countdown Timer for WooCommerce and WordPress CWE-98 7.5 High 2026-02-19
CVE-2026-2019 Cart All In One For WooCommerce <= 1.1.21 - Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting — Cart All In One For WooCommerce CWE-74 7.2 High 2026-02-18
CVE-2025-14541 Lucky Wheel Giveaway <= 1.0.22 - Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter — Lucky Wheel Giveaway CWE-94 7.2 High 2026-02-11
CVE-2025-14509 Lucky Wheel for WooCommerce – Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags — Lucky Wheel for WooCommerce – Spin a Sale CWE-94 7.2 High 2025-12-30
CVE-2025-68550 WordPress WPBulky plugin <= 1.1.13 - SQL Injection vulnerability — WPBulky CWE-89 7.6 High 2025-12-23
CVE-2025-68556 WordPress HAPPY plugin <= 1.0.9 - Broken Access Control vulnerability — HAPPY CWE-862 5.3 Medium 2025-12-23
CVE-2025-14581 HAPPY – Helpdesk Support Ticket System <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket Reply — HAPPY – Helpdesk Support Ticket System CWE-862 4.3 Medium 2025-12-13
CVE-2025-66528 WordPress Thank You Page Customizer for WooCommerce plugin <= 1.1.8 - Broken Access Control vulnerability — Thank You Page Customizer for WooCommerce CWE-862 4.3 Medium 2025-12-09
CVE-2025-49372 WordPress HAPPY plugin <= 1.0.7 - Remote Code Execution (RCE) vulnerability — HAPPY CWE-94 10.0 Critical 2025-11-06
CVE-2025-64200 WordPress Email Template Customizer for WooCommerce plugin <= 1.2.17 - Cross Site Scripting (XSS) vulnerability — Email Template Customizer for WooCommerce CWE-79 5.9 Medium 2025-10-29
CVE-2025-47570 WordPress WooCommerce Photo Reviews plugin <= 1.3.13 - Cross Site Scripting (XSS) vulnerability — WooCommerce Photo Reviews CWE-79 7.1 High 2025-09-09
CVE-2025-53571 WordPress HAPPY plugin <= 1.0.6 - Broken Access Control vulnerability — HAPPY CWE-862 6.5 Medium 2025-09-05
CVE-2025-30993 WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.7 - Broken Access Control Vulnerability — Thank You Page Customizer for WooCommerce CWE-862 6.5 Medium 2025-08-14
CVE-2025-47563 WordPress CURCY plugin <= 2.3.7 - Arbitrary Shortcode Execution vulnerability — CURCY CWE-862 5.3 Medium 2025-05-16
CVE-2024-13320 CURCY - WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection — CURCY - WooCommerce Multi Currency - Currency Switcher CWE-89 7.5 High 2025-03-07
CVE-2024-13487 CURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function — CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x CWE-94 7.3 High 2025-02-06
CVE-2024-12861 W2S – Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read — W2S – Migrate WooCommerce to Shopify CWE-73 6.5 Medium 2025-01-30
CVE-2025-22803 WordPress Advanced Product Information for WooCommerce plugin <= 1.1.4 - Cross Site Scripting (XSS) vulnerability — Advanced Product Information for WooCommerce CWE-79 6.5 Medium 2025-01-09

This page lists every published CVE security advisory associated with Villatheme. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.