ThemeGrill Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with ThemeGrill products.
Products
- ColorMag3 vulnerabilities
- Masteriyo - LMS3 vulnerabilities
- Himalayas2 vulnerabilities
- Maintenance Page2 vulnerabilities
- ThemeGrill Demo Importer2 vulnerabilities
- themegrill_demo_importer2 vulnerabilities
- User Registration2 vulnerabilities
- User Registration Stripe2 vulnerabilities
- Zakra2 vulnerabilities
- Accelerate1 vulnerability
- ColorNews1 vulnerability
- Esteem1 vulnerability
- maintenance_page1 vulnerability
- Registration Form for WooCommerce1 vulnerability
- Spacious1 vulnerability
- ThemeGrill Demo Importer plugin for WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-9266MEDIUM | Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin InstallationThe Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enqueue_scripts() function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ThemeGrill Demo Importer plugin. CWE-862Aug 6, 2026 | CVSS4.3v3.1 | EPSS0.158% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4804MEDIUM | Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST APIThe Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is due to the theme registering three post meta fields (zakra_menu_item_color, zakra_menu_item_hover_color, and zakra_menu_item_active_color) with 'show_in_rest' => true and 'auth_callback' => '__return_true', but without any sanitize_callback parameter in the register_post_meta() calls. While the classic editor save path applies sanitize_hex_color() s… CWE-79Jul 3, 2026 | CVSS6.4v3.1 | EPSS0.177% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-52701MEDIUM | WordPress User Registration plugin <= 5.2.2 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in User Registration <= 5.2.2 versions. CWE-862Jun 26, 2026 | CVSS6.5v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-54807CRITICAL | WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerabilityUnauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. CWE-266Jun 17, 2026 | CVSS9.8v3.1 | EPSS0.437% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-49081HIGH | WordPress User Registration Stripe plugin <= 1.3.12 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. CWE-862Jun 17, 2026 | CVSS8.2v3.1 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40726HIGH | WordPress User Registration Stripe plugin <= 1.3.14 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions. CWE-862Jun 17, 2026 | CVSS8.2v3.1 | EPSS0.244% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42743MEDIUM | WordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerabilityUnauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions. CWE-347Jun 15, 2026 | CVSS6.5v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-39524HIGH | WordPress Masteriyo - LMS plugin <= 2.1.5 - Payment Bypass vulnerabilityUnauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions. CWE-862Jun 15, 2026 | CVSS7.5v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25425HIGH | WordPress User Registration plugin <= 5.1.2 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in User Registration <= 5.1.2 versions. CWE-862Jun 15, 2026 | CVSS7.5v3.1 | EPSS0.372% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-49111HIGH | WordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerabilityIncorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0. CWE-266Jun 15, 2026 | CVSS8.8v3.1 | EPSS0.238% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40730MEDIUM | WordPress ThemeGrill Demo Importer plugin <= 2.0.0.6 - Broken Access Control vulnerabilityMissing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.0.0.6. CWE-862Apr 15, 2026 | CVSS5.3v3.1 | EPSS0.195% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9331MEDIUM | Spacious <= 1.9.11 - Missing Authorization to Autheticated (Subscriber+) Demo Data ImportThe Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo data into the site. CWE-862Aug 22, 2025 | CVSS4.3v3.1 | EPSS0.304% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9202MEDIUM | ColorMag <= 4.0.19 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin InstallationThe ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the ThemeGrill Demo Importer plugin. CWE-862Aug 20, 2025 | CVSS4.3v3.1 | EPSS0.227% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-8595MEDIUM | Zakra <= 4.1.5 - Missing Authorization to Subscriber+ Demo ImportThe Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo settings. CWE-862Aug 6, 2025 | CVSS4.3v3.1 | EPSS0.221% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36837CRITICAL | ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site ResetThe ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 through 1.6.1. This makes it possible for authenticated attackers to reset the WordPress database. After which, if there is a user named 'admin', the attacker will become automatically logged in as an administrator. CWE-862Oct 16, 2024 | CVSS9.9v3.1 | EPSS0.584% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-39629MEDIUM | WordPress Himalayas theme <= 1.3.2 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.2. CWE-79Aug 1, 2024 | CVSS5.9v3.1 | EPSS0.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37432MEDIUM | WordPress Esteem theme <= 1.5.0 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Esteem allows Stored XSS.This issue affects Esteem: from n/a through 1.5.0. CWE-79Jul 22, 2024 | CVSS5.9v3.1 | EPSS0.263% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34571MEDIUM | WordPress Himalayas theme <= 1.3.0 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.0. CWE-79May 8, 2024 | CVSS6.5v3.1 | EPSS0.255% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33540MEDIUM | WordPress ColorNews theme <= 1.2.6 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill ColorNews allows Stored XSS.This issue affects ColorNews: from n/a through 1.2.6. CWE-79Apr 29, 2024 | CVSS6.5v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2500MEDIUM | ColorMag <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Display NameThe ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authentciated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Mar 22, 2024 | CVSS6.4v3.1 | EPSS0.424% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1462MEDIUM | Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST APIThe Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles and content when the site is in maintenance mode. CWE-284Mar 13, 2024 | CVSS5.3v3.1 | EPSS0.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1370MEDIUM | Maintenance Page <= 1.0.8 - Missing Authorization to Sensitive Information ExposureThe Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber access or higher, to download a csv containing subscriber emails. | CVSS5.3v3.1 | EPSS0.445% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0679MEDIUM | ColorMag <= 3.1.2 - Missing Authorization to Arbitrary Plugin InstallationThe ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins. CWE-862Jan 20, 2024 | CVSS6.5v3.1 | EPSS1.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36333CRITICAL | themegrill themegrill_demo_importer Missing Authentication for Critical Functionthemegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook. | CVSS9.1v3.1 | EPSS4.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |