Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

themeisle — Vulnerabilities & Security Advisories 86

Browse all 86 CVE security advisories affecting themeisle. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Themeisle operates as a developer of WordPress plugins and themes, primarily offering free and premium tools for site optimization, SEO, and design. Its extensive portfolio has historically been associated with a significant volume of security vulnerabilities, currently totaling 86 recorded CVEs. These flaws predominantly involve cross-site scripting (XSS), SQL injection, and unauthenticated remote code execution (RCE), often stemming from insufficient input validation and weak access controls within plugin code. Notable incidents include critical RCE vulnerabilities in popular plugins like OceanWP and Zakra, which allowed attackers to execute arbitrary commands on compromised servers. The high frequency of these issues highlights systemic challenges in maintaining rigorous security standards across a large, diverse suite of open-source and commercial web components, necessitating frequent updates and strict adherence to secure coding practices to mitigate risks for end-users.

Found 10 results / 86Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2024-10705 Multiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrl — Multiple Page Generator Plugin – MPGCWE-918 5.4 Medium2025-01-26
CVE-2024-10672 Multiple Page Generator Plugin – MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File Deletion — Multiple Page Generator Plugin – MPGCWE-73 2.7 Low2024-11-12
CVE-2024-7424 Multiple Page Generator Plugin – MPG <= 4.0.1 - Missing Authorization — Multiple Page Generator Plugin – MPGCWE-284 5.4 Medium2024-11-01
CVE-2024-31301 WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) vulnerability — Multiple Page Generator Plugin – MPGCWE-352 5.4 Medium2024-04-12
CVE-2024-27951 WordPress Multiple Page Generator Plugin <= 3.4.0 - Auth. Remote Code Execution (RCE) vulnerability — Multiple Page Generator Plugin – MPGCWE-434 9.1 Critical2024-04-03
CVE-2024-30235 WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Broken Access Control vulnerability — Multiple Page Generator Plugin – MPGCWE-862 4.3 Medium2024-03-26
CVE-2023-33927 WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.19 is vulnerable to SQL Injection — Multiple Page Generator Plugin – MPGCWE-89 7.6 High2023-10-31
CVE-2023-2607 Multiple Page Generator Plugin <= 3.3.17 - Authenticated (Administrator+) SQL Injection — Multiple Page Generator Plugin – MPGCWE-89 7.2 High2023-06-09
CVE-2023-2608 Multiple Page Generator Plugin <= 3.3.17 - Cross-Site Request Forgery to SQL Injection — Multiple Page Generator Plugin – MPGCWE-352 3.1 Low2023-05-17
CVE-2022-47143 WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF) — Multiple Page Generator Plugin – MPGCWE-352 4.3 Medium2023-03-14

This page lists every published CVE security advisory associated with themeisle. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.