Apollo13themes develops WordPress theme extensions and template products, a modestly represented vendor presence within a niche of page-builder customization tools. The recurring vulnerability signal centers on client-side input handling, with cross-site scripting and cross-site request forgery appearing across its framework extensions and free template offerings—weakness classes typical of web-facing customization layers where user input flows directly into rendered content. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apollo13themes over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13617MEDIUM The Apollo13 Framework Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a13_alt_link’ parameter in all versions up to, and including, 1.9.8 due | Feb 19, 2026 | 6.4 | 21 | NO | NO |
CVE-2023-51539HIGH Cross-Site Request Forgery (CSRF) vulnerability in Apollo13Themes Apollo13 Framework Extensions.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.1. | Jan 5, 2024 | 8.8 | 21 | NO | NO |
CVE-2023-47190MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plugin <= 1.9.0 versions. | Nov 8, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-24265MEDIUM The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as cont | May 5, 2021 | 5.4 | 19 | NO | NO |
CVE-2023-27454MEDIUM Missing Authorization vulnerability in Apollo13Themes Rife Elementor Extensions & Templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec | Dec 9, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-35708MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in apollo13themes Rife Free allows Stored XSS.This issue affects Rife Free | Jun 8, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-25959MEDIUM Missing Authorization vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apoll | Dec 9, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-37480MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions apollo13-framework-extensi | Jul 21, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-5504MEDIUM The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute within the plugin's Writing Effect Headline widg | Jul 2, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-24880MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Stored XSS.This issue affe | Feb 8, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apollo13themes.
Media articles that mention a CVE ID that affects a product developed by Apollo13themes — matched by CVE ID, not by vendor name.