Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Machothemes

First CVE: Jun 22, 2020Active for: 6 yearsTotal CVEs: 11
23.6
VTI Score
Low

Machothemes develops a focused portfolio of WordPress themes and plugins, primarily targeting photography, news, and content-rich websites. Its vulnerability profile centers on web-application input-handling and access-control weaknesses—cross-site scripting, code injection, improper access control, and missing authorization—that are endemic to community-contributed WordPress ecosystem components. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Machothemes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 22, 2020
6 years ago
Most Recent CVE
Feb 27, 2025
513 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-36708CRITICAL
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, All
Jun 7, 20239.874NOYES
CVE-2020-36721MEDIUM
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_
Jun 7, 20236.520NONO
CVE-2023-28493MEDIUM
Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes NewsMag theme <= 2.4.4 versions.
May 8, 20235.420NONO
CVE-2023-27619MEDIUM
Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 versions.
Apr 25, 20235.420NONO
CVE-2022-4717MEDIUM
The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users
Feb 6, 20235.420NONO
CVE-2022-0186MEDIUM
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low
Feb 21, 20225.420NONO
CVE-2020-14962MEDIUM
Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTit
Jun 22, 20205.420NONO
CVE-2022-4837MEDIUM
The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with
Jan 30, 20235.419NONO
CVE-2023-0162MEDIUM
The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due
Jan 10, 20234.819NONO
CVE-2024-33916MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MachoThemes CPO Companion allows Stored XSS.This issue affects CPO Companion:
May 3, 20246.518NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
91%
9%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (18.2%)
Unknown0 (0.0%)
Required9 (81.8%)
Privileges Required
Low8 (72.7%)
High1 (9.1%)
None2 (18.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Machothemes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Machothemes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Machothemes's Products

View all 4 CNAs →

Top CWEs