Skip to content
Noroxi

themehunk records

23 published records for vendor themehunk.

All records

23 records
  • Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation

    CriticalCVSS 9.8Proof of conceptEPSS 54%

    themehunk · hunk companionDec 31, 2024

  • WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add

    CriticalCVSS 9.8Proof of conceptEPSS 52%

    themehunk · wp popup builderOct 16, 2024

  • Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    themehunk · hunk companionOct 11, 2024

  • WordPress TH Advance Product Search plugin <= 1.2.1 - Unauthenticated Plugin Settings Reset vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    themehunk · th advance product searchMar 25, 2024

  • WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    themehunk · zitaJun 27, 2025

  • WordPress TH Advance Product Search plugin <= 1.1.4 - Unauthenticated Plugin Settings Change vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    themehunk · advance product searchMay 8, 2024

  • Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

    HighCVSS 8.8Proof of conceptEPSS 2%

    themehunk · th shop maniaNov 9, 2024

  • Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

    HighCVSS 8.8Proof of conceptEPSS 1%

    themehunk · top storeNov 9, 2024

  • WordPress Big Store Theme <= 1.9.3 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    themehunk · big storeNov 12, 2023

  • WordPress Vayu Blocks – Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    themehunk · vayu blocksMar 27, 2025

  • Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    themehunk · contact form \& lead form elementor builderDec 27, 2021

  • CVE-2022-2404
    24Monitor

    WP Popup Builder < 1.2.9 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    themehunk · wp popup builderSep 26, 2022

  • CVE-2024-3637
    24Monitor

    Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Admin+ Stored XSS

    MediumCVSS 6.1No exploitEPSS 0%

    themehunk · contact form \& lead form elementor builderMay 3, 2024

  • WordPress Big Store theme <= 2.0.8 - Broken Access Control vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    themehunk · big storeMar 27, 2025

  • WordPress WP Popup Builder plugin <= 1.3.8 - Sensitive Data Exposure vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    themehunk · wp popup builderOct 26, 2025

  • WordPress Gutenberg Blocks – Unlimited blocks For Gutenberg plugin <= 1.2.8 - Authenticated Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    themehunk · gutenberg blocksSep 17, 2024

  • WordPress ThemeHunk plugin <= 1.2.0 - Broken Access Control vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    themehunk · mega menuJun 6, 2025

  • WordPress TH Variation Swatches plugin <= 1.2.7 - Cross-Site Request Forgery (CSRF) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    themehunk · variation swatchesDec 9, 2024

  • Contact Form & Lead Form Elementor Builder < 1.7.0 - Multiple Admin+ Stored Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 1%

    themehunk · contact form \& lead form elementor builderJan 16, 2024

  • Lead Form Builder < 1.9.8 - Admin+ Stored XSS

    MediumCVSS 4.8No exploitEPSS 0%

    themehunk · contact form \& lead form elementor builderMay 15, 2025

  • Contact Form & Lead Form Elementor Builder Plugin < 1.7.4 - Multiple Subscriber+ Settings Update

    MediumCVSS 4.3No exploitEPSS 1%

    themehunk · contact form \& lead form elementor builderJan 16, 2024

  • CVE-2024-8434
    17Monitor

    Easy Mega Menu Plugin for WordPress – ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Settings Updates

    MediumCVSS 4.3No exploitEPSS 0%

    themehunk · mega menuSep 24, 2024

  • CVE-2022-2405
    17Monitor

    WP Popup Builder < 1.3.0 - Subscriber+ Arbitrary Popup Deletion

    MediumCVSS 4.3No exploitEPSS 0%

    themehunk · wp popup builderSep 26, 2022