Mythemeshop develops a suite of WordPress plugins and themes, including URL shortening, translation, subscription, and shortcode utilities that extend site functionality for a distributed user base. The vendor's vulnerability exposure concentrates on web-application input-handling and authorization weaknesses—chiefly cross-site scripting, cross-site request forgery, and missing authorization controls—that are characteristic of plugin-based WordPress extensions where trust boundaries and input sanitization are critical. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mythemeshop over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8425HIGH The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_impo | Sep 11, 2025 | 8.8 | 29 | NO | NO |
CVE-2023-23896HIGH Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17. | Jan 17, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-28495HIGH Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions. | Nov 12, 2023 | 8.8 | 25 | NO | NO |
CVE-2017-18569HIGH The my-wp-translate plugin before 1.0.4 for WordPress has CSRF. | Aug 20, 2019 | 8.8 | 25 | NO | NO |
CVE-2023-30472MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions. | Sep 27, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-8423MEDIUM The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_plugin() and ajax_update_export_c | Sep 11, 2025 | 5.4 | 20 | NO | NO |
CVE-2021-36829MEDIUM Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress. | Sep 6, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-36844MEDIUM Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress. | May 2, 2022 | 4.8 | 19 | NO | NO |
CVE-2017-18568MEDIUM The my-wp-translate plugin before 1.0.4 for WordPress has XSS. | Aug 20, 2019 | 6.1 | 19 | NO | NO |
CVE-2024-5802MEDIUM The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross- | Jul 9, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mythemeshop.
Media articles that mention a CVE ID that affects a product developed by Mythemeshop — matched by CVE ID, not by vendor name.