Blossomthemes develops a focused line of WordPress plugins and themes spanning recipe management, e-commerce, spa booking, and email newsletter functionality, each presenting a web-facing application attack surface. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, while the recurring weakness classes—cross-site request forgery, cross-site scripting, missing authorization, and server-side request forgery—reflect the input-validation and access-control demands of plugin-based WordPress extensions. Defenders should prioritize patches for internet-exposed WordPress sites running these products; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blossomthemes over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37098CRITICAL Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6. | Jun 26, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-37412HIGH Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Blossom Shop blossom-shop allows Cross Site Request Forgery.This issue affects Blossom Shop: from n/a through <= 1. | Jan 2, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-37102HIGH Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Vilva vilva allows Cross Site Request Forgery.This issue affects Vilva: from n/a through <= 1.2.2. | Jan 2, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-31429HIGH Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Sarada Lite.This issue affects Sarada Lite: from n/a through 1.1.2. | Apr 15, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-2107HIGH The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.3 via generated source. This makes it possible for una | Mar 12, 2024 | 7.5 | 22 | NO | NO |
CVE-2022-37338MEDIUM Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <= 1.0.7 at WordPress. | Sep 23, 2022 | 5.4 | 20 | NO | NO |
CVE-2024-37243MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Vandana Lite vandana-lite allows Cross Site Request Forgery.This issue affects Vandana Lite: from n/a through <= 1. | Jan 2, 2025 | 4.3 | 15 | NO | NO |
CVE-2023-47849MEDIUM Missing Authorization vulnerability in Blossom Themes BlossomThemes Email Newsletter blossomthemes-email-newsletter allows Exploiting Incorrectly Configured Access Control Security | Dec 9, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blossomthemes.
Media articles that mention a CVE ID that affects a product developed by Blossomthemes — matched by CVE ID, not by vendor name.