Presscustomizr develops a focused line of WordPress themes and page-builder plugins, including Customizr, Hueman, and Nimble Page Builder, that are embedded across many WordPress installations despite the vendor's modest disclosure volume. The recurring vulnerabilities center on web-application input-handling weaknesses, particularly cross-site request forgery and cross-site scripting flaws that are characteristic of theme and plugin codebases operating within WordPress's content-management context. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Presscustomizr over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-35772HIGH Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Hueman.This issue affects Hueman: from n/a through 3.7.24. | Jun 21, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-35771HIGH Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Customizr.This issue affects Customizr: from n/a through 4.4.21. | Jun 21, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-4784MEDIUM The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is emb | Feb 21, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-0314MEDIUM The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cr | Apr 11, 2022 | 6.1 | 17 | NO | NO |
CVE-2020-36755MEDIUM The Customizr theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. This is due to missing or incorrect nonce validation on the c | Oct 20, 2023 | 4.3 | 16 | NO | NO |
CVE-2020-36753MEDIUM The Hueman theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation on the save | Oct 20, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Presscustomizr.
Media articles that mention a CVE ID that affects a product developed by Presscustomizr — matched by CVE ID, not by vendor name.