Exthemes develops WordPress plugin products focused on e-commerce and events functionality, including WooCommerce Food and WooEvents, where vulnerabilities have centered on improper code generation and path-traversal weaknesses in plugin code. These weakness classes reflect common risks in WordPress extensions where user input flows into code execution or file access operations without sufficient isolation or validation. Current vulnerability counts, severity breakdown, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exthemes over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8671CRITICAL The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in al | Sep 24, 2024 | 9.1 | 29 | NO | NO |
CVE-2024-13792CRITICAL The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due | Feb 20, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-60121MEDIUM Missing Authorization vulnerability in Ex-Themes WooEvents woo-events allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooEvents: from n/a | Sep 26, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exthemes.
Media articles that mention a CVE ID that affects a product developed by Exthemes — matched by CVE ID, not by vendor name.