G5theme develops WordPress themes including Grid Plus and Essential Real Estate that are deployed across real-estate and small-business websites. Its vulnerability profile centers on web-application input-handling issues, particularly PHP remote file inclusion and cross-site scripting vulnerabilities that are common vectors in theme and plugin ecosystems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by G5theme over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3933MEDIUM The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scr | Dec 12, 2022 | 5.4 | 29 | NO | YES |
CVE-2023-5250HIGH The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allows subscriber-level, and above, | Oct 30, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-53352HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Grid Plus grid-plus allows Reflected XSS.This issue affects Grid Plus: | Oct 22, 2025 | 7.1 | 23 | NO | NO |
CVE-2023-46209MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in G5Theme Grid Plus – Unlimited grid plugin <= 1.3.2 versions. | Oct 27, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-5251MEDIUM The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid_plus_save_layout_callback' and | Oct 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-34014MEDIUM Missing Authorization vulnerability in G5Theme Grid Plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grid Plus: from n/a through 1.3. | Dec 13, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by G5theme.
Media articles that mention a CVE ID that affects a product developed by G5theme — matched by CVE ID, not by vendor name.