Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Villatheme — Vulnerabilities & Security Advisories 64

Browse all 64 CVE security advisories affecting Villatheme. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Villatheme operates as a provider of WordPress themes and plugins, primarily targeting niche markets such as gaming, streaming, and multimedia content. Security audits reveal a concerning pattern of forty documented Common Vulnerabilities and Exposures (CVEs), indicating systemic weaknesses in the development lifecycle. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper sanitization of user-supplied data. Additionally, instances of broken access control and privilege escalation have been recorded, allowing unauthorized users to manipulate administrative functions. These flaws frequently arise from outdated codebases and a lack of rigorous security testing before deployment. The high volume of CVEs suggests that Villatheme products pose significant risks to website integrity, potentially enabling attackers to compromise entire server environments through simple exploitation of these known entry points.

CVE ID Title CVSS Severity Published
CVE-2025-14541 Lucky Wheel Giveaway <= 1.0.22 - Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter — Lucky Wheel Giveaway CWE-94 7.2 High 2026-02-11
CVE-2025-14509 Lucky Wheel for WooCommerce – Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags — Lucky Wheel for WooCommerce – Spin a Sale CWE-94 7.2 High 2025-12-30
CVE-2025-68550 WordPress WPBulky plugin <= 1.1.13 - SQL Injection vulnerability — WPBulky CWE-89 7.6 High 2025-12-23
CVE-2025-68556 WordPress HAPPY plugin <= 1.0.9 - Broken Access Control vulnerability — HAPPY CWE-862 5.3 Medium 2025-12-23
CVE-2025-14581 HAPPY – Helpdesk Support Ticket System <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket Reply — HAPPY – Helpdesk Support Ticket System CWE-862 4.3 Medium 2025-12-13
CVE-2025-66528 WordPress Thank You Page Customizer for WooCommerce plugin <= 1.1.8 - Broken Access Control vulnerability — Thank You Page Customizer for WooCommerce CWE-862 4.3 Medium 2025-12-09
CVE-2025-49372 WordPress HAPPY plugin <= 1.0.7 - Remote Code Execution (RCE) vulnerability — HAPPY CWE-94 10.0 Critical 2025-11-06
CVE-2025-64200 WordPress Email Template Customizer for WooCommerce plugin <= 1.2.17 - Cross Site Scripting (XSS) vulnerability — Email Template Customizer for WooCommerce CWE-79 5.9 Medium 2025-10-29
CVE-2025-47570 WordPress WooCommerce Photo Reviews plugin <= 1.3.13 - Cross Site Scripting (XSS) vulnerability — WooCommerce Photo Reviews CWE-79 7.1 High 2025-09-09
CVE-2025-53571 WordPress HAPPY plugin <= 1.0.6 - Broken Access Control vulnerability — HAPPY CWE-862 6.5 Medium 2025-09-05
CVE-2025-30993 WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.7 - Broken Access Control Vulnerability — Thank You Page Customizer for WooCommerce CWE-862 6.5 Medium 2025-08-14
CVE-2025-47563 WordPress CURCY plugin <= 2.3.7 - Arbitrary Shortcode Execution vulnerability — CURCY CWE-862 5.3 Medium 2025-05-16
CVE-2024-13320 CURCY - WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection — CURCY - WooCommerce Multi Currency - Currency Switcher CWE-89 7.5 High 2025-03-07
CVE-2024-13487 CURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function — CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x CWE-94 7.3 High 2025-02-06
CVE-2024-12861 W2S – Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read — W2S – Migrate WooCommerce to Shopify CWE-73 6.5 Medium 2025-01-30
CVE-2025-22803 WordPress Advanced Product Information for WooCommerce plugin <= 1.1.4 - Cross Site Scripting (XSS) vulnerability — Advanced Product Information for WooCommerce CWE-79 6.5 Medium 2025-01-09
CVE-2022-46796 WordPress CURCY plugin <= 2.1.25 - Unauthenticated plugin settings change vulnerability — CURCY CWE-862 6.5 Medium 2024-12-13
CVE-2024-49283 WordPress CURCY plugin <= 2.2.3 - Reflected Cross Site Scripting (XSS) vulnerability — CURCY CWE-79 7.1 High 2024-10-17
CVE-2024-49288 WordPress Email Template Customizer for WooCommerce plugin <= 1.2.9.1 - Cross Site Scripting (XSS) vulnerability — Email Template Customizer for WooCommerce CWE-79 5.9 Medium 2024-10-17
CVE-2024-8277 WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation — WooCommerce Photo Reviews Premium CWE-288 9.8 Critical 2024-09-11
CVE-2024-4039 Orders Tracking for WooCommerce <= 1.2.10 - Unauthenticated Arbitrary Shortcode Execution — Orders Tracking for WooCommerce CWE-94 6.5 Medium 2024-05-10
CVE-2024-1687 Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution — Thank You Page Customizer for WooCommerce – Increase Your Sales CWE-862 5.4 Medium 2024-02-27
CVE-2024-1686 Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Data Export — Thank You Page Customizer for WooCommerce – Increase Your Sales CWE-862 4.3 Medium 2024-02-27
CVE-2023-50831 WordPress CURCY Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS) — CURCY – Multi Currency for WooCommerce CWE-79 6.5 Medium 2023-12-21
CVE-2023-48778 WordPress Product Size Chart For WooCommerce Plugin <= 1.1.5 is vulnerable to Cross Site Request Forgery (CSRF) — Product Size Chart For WooCommerce CWE-352 5.4 Medium 2023-12-18
CVE-2023-30482 WordPress WPBulky Plugin < 1.0.10 is vulnerable to Cross Site Scripting (XSS) — WPBulky CWE-79 6.5 Medium 2023-08-08
CVE-2021-4395 Abandoned Cart Recovery for WooCommerce <= 1.0.4 - Cross-Site Request Forgery Bypass — Abandoned Cart Recovery for WooCommerce CWE-352 4.3 Medium 2023-07-01
CVE-2021-4379 WooCommerce Multi Currency <= 2.1.17 - Missing Authorization — CURCY - WooCommerce Multi Currency - Currency Switcher CWE-862 6.5 Medium 2023-06-07
CVE-2021-4376 WooCommerce Multi Currency <= 2.1.17 - Missing Authorization — CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x CWE-862 4.3 Medium 2023-06-07
CVE-2022-46810 WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF) — Thank You Page Customizer for WooCommerce – Increase Your Sales CWE-352 4.3 Medium 2023-05-25

This page lists every published CVE security advisory associated with Villatheme. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.