Aivahthemes develops a narrow line of WordPress plugins, with documented exposure centered on its Business Hours Pro product and file-upload validation weaknesses. The recurring pattern involves unrestricted file-type uploads, a class of flaw that enables arbitrary code execution on affected WordPress installations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aivahthemes over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24240CRITICAL The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote | Apr 22, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aivahthemes.
Media articles that mention a CVE ID that affects a product developed by Aivahthemes — matched by CVE ID, not by vendor name.