Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Villatheme — Vulnerabilities & Security Advisories 41

Browse all 41 CVE security advisories affecting Villatheme. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-50831 WordPress CURCY Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS) — CURCY – Multi Currency for WooCommerceCWE-79 6.5 Medium2023-12-21
CVE-2023-48778 WordPress Product Size Chart For WooCommerce Plugin <= 1.1.5 is vulnerable to Cross Site Request Forgery (CSRF) — Product Size Chart For WooCommerceCWE-352 5.4 Medium2023-12-18
CVE-2023-30482 WordPress WPBulky Plugin < 1.0.10 is vulnerable to Cross Site Scripting (XSS) — WPBulkyCWE-79 6.5 Medium2023-08-08
CVE-2021-4395 Abandoned Cart Recovery for WooCommerce <= 1.0.4 - Cross-Site Request Forgery Bypass — Abandoned Cart Recovery for WooCommerceCWE-352 4.3 Medium2023-07-01
CVE-2021-4379 WooCommerce Multi Currency <= 2.1.17 - Missing Authorization — CURCY - WooCommerce Multi Currency - Currency SwitcherCWE-862 6.5 Medium2023-06-07
CVE-2021-4376 WooCommerce Multi Currency <= 2.1.17 - Missing Authorization — CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.xCWE-862 4.3 Medium2023-06-07
CVE-2022-46810 WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF) — Thank You Page Customizer for WooCommerce – Increase Your SalesCWE-352 4.3 Medium2023-05-25
CVE-2022-46812 WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF) — Thank You Page Customizer for WooCommerce – Increase Your SalesCWE-352 4.3 Medium2023-05-25
CVE-2022-46806 WordPress Cart All In One For WooCommerce Plugin <= 1.1.10 is vulnerable to Cross Site Request Forgery (CSRF) — Cart All In One For WooCommerceCWE-352 5.4 Medium2023-03-01
CVE-2022-44634 WordPress S2W – Import Shopify to WooCommerce plugin <= 1.1.12 - Auth. Arbitrary File Read vulnerability — S2W – Import Shopify to WooCommerce (WordPress plugin) 4.9 Medium2022-11-18
CVE-2022-41623 WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerability — ALD - AliExpress Dropshipping and Fulfillment for WooCommerce (WordPress plugin)CWE-202 7.5 High2022-10-14

This page lists every published CVE security advisory associated with Villatheme. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.