Machothemes develops a focused portfolio of WordPress themes and plugins, primarily targeting photography, news, and content-rich websites. Its vulnerability profile centers on web-application input-handling and access-control weaknesses—cross-site scripting, code injection, improper access control, and missing authorization—that are endemic to community-contributed WordPress ecosystem components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Machothemes over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36708CRITICAL The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, All | Jun 7, 2023 | 9.8 | 74 | NO | YES |
CVE-2020-36721MEDIUM The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_ | Jun 7, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-28493MEDIUM Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes NewsMag theme <= 2.4.4 versions. | May 8, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-27619MEDIUM Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 versions. | Apr 25, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-4717MEDIUM The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users | Feb 6, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-0186MEDIUM The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low | Feb 21, 2022 | 5.4 | 20 | NO | NO |
CVE-2020-14962MEDIUM Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTit | Jun 22, 2020 | 5.4 | 20 | NO | NO |
CVE-2022-4837MEDIUM The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with | Jan 30, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0162MEDIUM The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due | Jan 10, 2023 | 4.8 | 19 | NO | NO |
CVE-2024-33916MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MachoThemes CPO Companion allows Stored XSS.This issue affects CPO Companion: | May 3, 2024 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Machothemes.
Media articles that mention a CVE ID that affects a product developed by Machothemes — matched by CVE ID, not by vendor name.