themehunk records
23 published records for vendor themehunk.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 43.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization10
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2024-11972Proof of concept | Hunk Companion < 1.9.0 - Unauthenticated Plugin Installationthemehunk · hunk companion · CWE-862 | Critical9.8 | — | 54.5% | Dec 31, 2024 |
55Plan | CVE-2024-9061Proof of concept | WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Addthemehunk · wp popup builder · CWE-94 | Critical9.8 | — | 52.3% | Oct 16, 2024 |
42Plan | CVE-2024-9707Proof of concept | Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activationthemehunk · hunk companion · CWE-862 | Critical9.8 | — | 9.1% | Oct 11, 2024 |
39Monitor | CVE-2022-38057No exploit | WordPress TH Advance Product Search plugin <= 1.2.1 - Unauthenticated Plugin Settings Reset vulnerabilitythemehunk · th advance product search · CWE-862 | Critical9.8 | — | 0.6% | Mar 25, 2024 |
39Monitor | CVE-2025-52816No exploit | WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerabilitythemehunk · zita · CWE-98 | Critical9.8 | — | 0.5% | Jun 27, 2025 |
39Monitor | CVE-2022-40218No exploit | WordPress TH Advance Product Search plugin <= 1.1.4 - Unauthenticated Plugin Settings Change vulnerabilitythemehunk · advance product search · CWE-862 | Critical9.8 | — | 0.5% | May 8, 2024 |
36Monitor | CVE-2024-10674Proof of concept | Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activationthemehunk · th shop mania · CWE-862 | High8.8 | — | 1.7% | Nov 9, 2024 |
35Monitor | CVE-2024-10673Proof of concept | Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activationthemehunk · top store · CWE-862 | High8.8 | — | 1.2% | Nov 9, 2024 |
35Monitor | CVE-2023-27431No exploit | WordPress Big Store Theme <= 1.9.3 is vulnerable to Cross Site Request Forgery (CSRF)themehunk · big store · CWE-352 | High8.8 | — | 0.3% | Nov 12, 2023 |
26Monitor | CVE-2025-22644No exploit | WordPress Vayu Blocks – Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) vulnerabilitythemehunk · vayu blocks · CWE-79 | Medium6.5 | — | 0.3% | Mar 27, 2025 |
24Monitor | CVE-2021-24967No exploit | Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site Scriptingthemehunk · contact form \& lead form elementor builder · CWE-79 | Medium6.1 | — | 1.2% | Dec 27, 2021 |
24Monitor | CVE-2022-2404No exploit | WP Popup Builder < 1.2.9 - Reflected Cross-Site Scriptingthemehunk · wp popup builder · CWE-79 | Medium6.1 | — | 0.6% | Sep 26, 2022 |
24Monitor | CVE-2024-3637No exploit | Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Admin+ Stored XSSthemehunk · contact form \& lead form elementor builder · CWE-79 | Medium6.1 | — | 0.5% | May 3, 2024 |
21Monitor | CVE-2025-30881No exploit | WordPress Big Store theme <= 2.0.8 - Broken Access Control vulnerabilitythemehunk · big store · CWE-862 | Medium5.4 | — | 0.4% | Mar 27, 2025 |
21Monitor | CVE-2025-62902No exploit | WordPress WP Popup Builder plugin <= 1.3.8 - Sensitive Data Exposure vulnerabilitythemehunk · wp popup builder · CWE-497 | Medium5.3 | — | 0.3% | Oct 26, 2025 |
21Monitor | CVE-2024-44049No exploit | WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Authenticated Cross Site Scripting (XSS) vulnerabilitythemehunk · gutenberg blocks · CWE-79 | Medium5.4 | — | 0.3% | Sep 17, 2024 |
21Monitor | CVE-2025-30990No exploit | WordPress ThemeHunk plugin <= 1.2.0 - Broken Access Control vulnerabilitythemehunk · mega menu · CWE-862 | Medium5.4 | — | 0.3% | Jun 6, 2025 |
21Monitor | CVE-2023-28688No exploit | WordPress TH Variation Swatches plugin <= 1.2.7 - Cross-Site Request Forgery (CSRF) vulnerabilitythemehunk · variation swatches · CWE-352 | Medium5.4 | — | 0.2% | Dec 9, 2024 |
19Monitor | CVE-2022-23179No exploit | Contact Form & Lead Form Elementor Builder < 1.7.0 - Multiple Admin+ Stored Cross-Site Scriptingthemehunk · contact form \& lead form elementor builder · CWE-79 | Medium4.8 | — | 0.5% | Jan 16, 2024 |
19Monitor | CVE-2024-10475No exploit | Lead Form Builder < 1.9.8 - Admin+ Stored XSSthemehunk · contact form \& lead form elementor builder · CWE-79 | Medium4.8 | — | 0.3% | May 15, 2025 |
17Monitor | CVE-2022-23180No exploit | Contact Form & Lead Form Elementor Builder Plugin < 1.7.4 - Multiple Subscriber+ Settings Updatethemehunk · contact form \& lead form elementor builder · CWE-862 | Medium4.3 | — | 0.5% | Jan 16, 2024 |
17Monitor | CVE-2024-8434No exploit | Easy Mega Menu Plugin for WordPress – ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Settings Updatesthemehunk · mega menu · CWE-862 | Medium4.3 | — | 0.4% | Sep 24, 2024 |
17Monitor | CVE-2022-2405No exploit | WP Popup Builder < 1.3.0 - Subscriber+ Arbitrary Popup Deletionthemehunk · wp popup builder · CWE-352 | Medium4.3 | — | 0.3% | Sep 26, 2022 |
- CVE-2024-1197255Plan
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
CriticalCVSS 9.8Proof of conceptEPSS 54%themehunk · hunk companionDec 31, 2024
- CVE-2024-906155Plan
WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add
CriticalCVSS 9.8Proof of conceptEPSS 52%themehunk · wp popup builderOct 16, 2024
- CVE-2024-970742Plan
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
CriticalCVSS 9.8Proof of conceptEPSS 9%themehunk · hunk companionOct 11, 2024
- CVE-2022-3805739Monitor
WordPress TH Advance Product Search plugin <= 1.2.1 - Unauthenticated Plugin Settings Reset vulnerability
CriticalCVSS 9.8No exploitEPSS 1%themehunk · th advance product searchMar 25, 2024
- CVE-2025-5281639Monitor
WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%themehunk · zitaJun 27, 2025
- CVE-2022-4021839Monitor
WordPress TH Advance Product Search plugin <= 1.1.4 - Unauthenticated Plugin Settings Change vulnerability
CriticalCVSS 9.8No exploitEPSS 0%themehunk · advance product searchMay 8, 2024
- CVE-2024-1067436Monitor
Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
HighCVSS 8.8Proof of conceptEPSS 2%themehunk · th shop maniaNov 9, 2024
- CVE-2024-1067335Monitor
Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
HighCVSS 8.8Proof of conceptEPSS 1%themehunk · top storeNov 9, 2024
- CVE-2023-2743135Monitor
WordPress Big Store Theme <= 1.9.3 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%themehunk · big storeNov 12, 2023
- CVE-2025-2264426Monitor
WordPress Vayu Blocks – Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%themehunk · vayu blocksMar 27, 2025
- CVE-2021-2496724Monitor
Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%themehunk · contact form \& lead form elementor builderDec 27, 2021
- CVE-2022-240424Monitor
WP Popup Builder < 1.2.9 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%themehunk · wp popup builderSep 26, 2022
- CVE-2024-363724Monitor
Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Admin+ Stored XSS
MediumCVSS 6.1No exploitEPSS 0%themehunk · contact form \& lead form elementor builderMay 3, 2024
- CVE-2025-3088121Monitor
WordPress Big Store theme <= 2.0.8 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%themehunk · big storeMar 27, 2025
- CVE-2025-6290221Monitor
WordPress WP Popup Builder plugin <= 1.3.8 - Sensitive Data Exposure vulnerability
MediumCVSS 5.3No exploitEPSS 0%themehunk · wp popup builderOct 26, 2025
- CVE-2024-4404921Monitor
WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Authenticated Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%themehunk · gutenberg blocksSep 17, 2024
- CVE-2025-3099021Monitor
WordPress ThemeHunk plugin <= 1.2.0 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%themehunk · mega menuJun 6, 2025
- CVE-2023-2868821Monitor
WordPress TH Variation Swatches plugin <= 1.2.7 - Cross-Site Request Forgery (CSRF) vulnerability
MediumCVSS 5.4No exploitEPSS 0%themehunk · variation swatchesDec 9, 2024
- CVE-2022-2317919Monitor
Contact Form & Lead Form Elementor Builder < 1.7.0 - Multiple Admin+ Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 1%themehunk · contact form \& lead form elementor builderJan 16, 2024
- CVE-2024-1047519Monitor
Lead Form Builder < 1.9.8 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%themehunk · contact form \& lead form elementor builderMay 15, 2025
- CVE-2022-2318017Monitor
Contact Form & Lead Form Elementor Builder Plugin < 1.7.4 - Multiple Subscriber+ Settings Update
MediumCVSS 4.3No exploitEPSS 1%themehunk · contact form \& lead form elementor builderJan 16, 2024
- CVE-2024-843417Monitor
Easy Mega Menu Plugin for WordPress – ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Settings Updates
MediumCVSS 4.3No exploitEPSS 0%themehunk · mega menuSep 24, 2024
- CVE-2022-240517Monitor
WP Popup Builder < 1.3.0 - Subscriber+ Arbitrary Popup Deletion
MediumCVSS 4.3No exploitEPSS 0%themehunk · wp popup builderSep 26, 2022