Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

themehigh — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting themehigh. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Themehigh develops WordPress plugins primarily for form building, popup creation, and page enhancement. Historically, their plugins have frequently contained vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and improper capability checks. Security researchers have consistently identified multiple critical flaws across their products, with 11 CVEs recorded to date. Their plugins' broad permissions and integration with WordPress core functionality have made them attractive targets for exploitation, with some vulnerabilities allowing complete site compromise. Themehigh's security track record reflects common issues in the WordPress plugin ecosystem, highlighting the risks of insufficient security reviews in third-party extensions.

Found 1 results / 13 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-45217 WordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Authentication vulnerability — Stripe Payment Gateway for WooCommerce CWE-288 6.5 Medium 2026-05-25

This page lists every published CVE security advisory associated with themehigh. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.