Themewinter records
22 published records for vendor themewinter.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 54.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')3
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-73 External Control of File Name or Path1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2025-47539Proof of concept | WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerabilitythemewinter · eventin · CWE-266 | Critical9.8 | — | 27.9% | May 23, 2025 |
41Plan | CVE-2025-47445Proof of concept | WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerabilitythemewinter · eventin · CWE-23 | Critical9.8 | — | 5.1% | May 14, 2025 |
39Monitor | CVE-2023-47805No exploit | WordPress WPCafe plugin <= 2.2.22 - Broken Access Control vulnerabilitythemewinter · wpcafe · CWE-862 | Critical9.8 | — | 0.5% | Dec 9, 2024 |
35Monitor | CVE-2024-7149No exploit | Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusionthemewinter · eventin · CWE-22 | High8.8 | — | 1.0% | Sep 27, 2024 |
35Monitor | CVE-2025-1770No exploit | Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusionthemewinter · eventin · CWE-22 | High8.8 | — | 0.9% | Mar 20, 2025 |
35Monitor | CVE-2025-26964No exploit | WordPress Eventin plugin <= 4.0.20 - Local File Inclusion vulnerabilitythemewinter · eventin · CWE-98 | High8.8 | — | 0.8% | Feb 25, 2025 |
35Monitor | CVE-2024-5431No exploit | WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcodethemewinter · wpcafe · CWE-98 | High8.8 | — | 0.6% | Jun 25, 2024 |
35Monitor | CVE-2025-4796Proof of concept | Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeoverthemewinter · eventin · CWE-639 | High8.8 | — | 0.6% | Aug 8, 2025 |
35Monitor | CVE-2023-49756No exploit | WordPress Eventin plugin <= 3.3.52 - Authenticated Notice Dismissal Vulnerabilitythemewinter · eventin · CWE-862 | High8.8 | — | 0.6% | Dec 9, 2024 |
35Monitor | CVE-2024-56213No exploit | WordPress Eventin plugin <= 4.0.7 - Contributor+ Limited Local File Inclusion vulnerabilitythemewinter · eventin · CWE-35 | High8.8 | — | 0.6% | Dec 31, 2024 |
35Monitor | CVE-2024-37513No exploit | WordPress WPCafe plugin <= 2.2.27 - Local File Inclusion vulnerabilitythemewinter · wpcafe · CWE-22 | High8.8 | — | 0.6% | Jul 9, 2024 |
35Monitor | CVE-2024-43135No exploit | WordPress WPCafe plugin <= 2.2.28 - Local File Inclusion vulnerabilitythemewinter · wpcafe · CWE-22 | High8.8 | — | 0.5% | Aug 13, 2024 |
30Monitor | CVE-2025-39584No exploit | WordPress Eventin plugin <= 4.0.25 - Local File Inclusion Vulnerabilitythemewinter · eventin · CWE-98 | High7.5 | — | 0.9% | Apr 16, 2025 |
30Monitor | CVE-2025-3419Proof of concept | Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Readthemewinter · eventin · CWE-73 | High7.5 | — | 0.7% | May 8, 2025 |
24Monitor | CVE-2025-49321No exploit | WordPress Eventin plugin <= 4.0.28 - Cross Site Scripting (XSS) Vulnerabilitythemewinter · eventin · CWE-79 | Medium6.1 | — | 0.3% | Jun 27, 2025 |
21Monitor | CVE-2024-1122No exploit | Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin <= 3.3.50 - Missing Authorization to Unauthenticated Events Exportthemewinter · eventin · CWE-862 | Medium5.3 | — | 0.5% | Feb 9, 2024 |
21Monitor | CVE-2024-1855No exploit | WPCafe <= 2.2.23 - Unauthenticated Blind Server-Side Request Forgerythemewinter · wpcafe · CWE-918 | Medium5.3 | — | 0.4% | May 22, 2024 |
21Monitor | CVE-2025-1766No exploit | Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Updatethemewinter · eventin · CWE-862 | Medium5.3 | — | 0.4% | Mar 20, 2025 |
21Monitor | CVE-2024-5427No exploit | WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting themewinter · wpcafe · CWE-79 | Medium5.4 | — | 0.3% | May 31, 2024 |
21Monitor | CVE-2024-37507No exploit | WordPress Eventin plugin <= 3.3.57 - Cross Site Scripting (XSS) vulnerabilitythemewinter · eventin · CWE-79 | Medium5.4 | — | 0.3% | Jul 21, 2024 |
19Monitor | CVE-2024-39648No exploit | WordPress Eventin plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerabilitythemewinter · eventin · CWE-79 | Medium4.8 | — | 0.3% | Aug 1, 2024 |
17Monitor | CVE-2024-6033No exploit | Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Importthemewinter · eventin · CWE-862 | Medium4.3 | — | 0.4% | Jul 17, 2024 |
- CVE-2025-4753947Plan
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 28%themewinter · eventinMay 23, 2025
- CVE-2025-4744541Plan
WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 5%themewinter · eventinMay 14, 2025
- CVE-2023-4780539Monitor
WordPress WPCafe plugin <= 2.2.22 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%themewinter · wpcafeDec 9, 2024
- CVE-2024-714935Monitor
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion
HighCVSS 8.8No exploitEPSS 1%themewinter · eventinSep 27, 2024
- CVE-2025-177035Monitor
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion
HighCVSS 8.8No exploitEPSS 1%themewinter · eventinMar 20, 2025
- CVE-2025-2696435Monitor
WordPress Eventin plugin <= 4.0.20 - Local File Inclusion vulnerability
HighCVSS 8.8No exploitEPSS 1%themewinter · eventinFeb 25, 2025
- CVE-2024-543135Monitor
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcode
HighCVSS 8.8No exploitEPSS 1%themewinter · wpcafeJun 25, 2024
- CVE-2025-479635Monitor
Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover
HighCVSS 8.8Proof of conceptEPSS 1%themewinter · eventinAug 8, 2025
- CVE-2023-4975635Monitor
WordPress Eventin plugin <= 3.3.52 - Authenticated Notice Dismissal Vulnerability
HighCVSS 8.8No exploitEPSS 1%themewinter · eventinDec 9, 2024
- CVE-2024-5621335Monitor
WordPress Eventin plugin <= 4.0.7 - Contributor+ Limited Local File Inclusion vulnerability
HighCVSS 8.8No exploitEPSS 1%themewinter · eventinDec 31, 2024
- CVE-2024-3751335Monitor
WordPress WPCafe plugin <= 2.2.27 - Local File Inclusion vulnerability
HighCVSS 8.8No exploitEPSS 1%themewinter · wpcafeJul 9, 2024
- CVE-2024-4313535Monitor
WordPress WPCafe plugin <= 2.2.28 - Local File Inclusion vulnerability
HighCVSS 8.8No exploitEPSS 1%themewinter · wpcafeAug 13, 2024
- CVE-2025-3958430Monitor
WordPress Eventin plugin <= 4.0.25 - Local File Inclusion Vulnerability
HighCVSS 7.5No exploitEPSS 1%themewinter · eventinApr 16, 2025
- CVE-2025-341930Monitor
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read
HighCVSS 7.5Proof of conceptEPSS 1%themewinter · eventinMay 8, 2025
- CVE-2025-4932124Monitor
WordPress Eventin plugin <= 4.0.28 - Cross Site Scripting (XSS) Vulnerability
MediumCVSS 6.1No exploitEPSS 0%themewinter · eventinJun 27, 2025
- CVE-2024-112221Monitor
Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin <= 3.3.50 - Missing Authorization to Unauthenticated Events Export
MediumCVSS 5.3No exploitEPSS 0%themewinter · eventinFeb 9, 2024
- CVE-2024-185521Monitor
WPCafe <= 2.2.23 - Unauthenticated Blind Server-Side Request Forgery
MediumCVSS 5.3No exploitEPSS 0%themewinter · wpcafeMay 22, 2024
- CVE-2025-176621Monitor
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update
MediumCVSS 5.3No exploitEPSS 0%themewinter · eventinMar 20, 2025
- CVE-2024-542721Monitor
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%themewinter · wpcafeMay 31, 2024
- CVE-2024-3750721Monitor
WordPress Eventin plugin <= 3.3.57 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%themewinter · eventinJul 21, 2024
- CVE-2024-3964819Monitor
WordPress Eventin plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%themewinter · eventinAug 1, 2024
- CVE-2024-603317Monitor
Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import
MediumCVSS 4.3No exploitEPSS 0%themewinter · eventinJul 17, 2024