Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Purethemes

First CVE: Apr 22, 2021Active for: 5 yearsTotal CVEs: 12
39.7
VTI Score
Medium

Purethemes develops a focused line of WordPress-based themes and plugins for real estate, job marketplace, and service-listing applications, a niche portfolio that concentrates in web application and access-control attack surfaces. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, with recurring weaknesses including cross-site scripting, improper access control, authorization bypass, and privilege management flaws that are characteristic of WordPress-adjacent web applications. Defenders deploying these themes should prioritize tracking updates and restricting administrative access; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Purethemes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2021
5 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-57786HIGH
Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.
Jul 13, 20268.835NONO
CVE-2021-24237MEDIUM
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before out
Apr 22, 20216.131NOYES
CVE-2025-67960HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout-Core workscout-core allows Reflected XSS.This issue affec
Jan 22, 20267.127NONO
CVE-2025-67959HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout workscout allows Reflected XSS.This issue affects WorkSco
Jan 22, 20267.127NONO
CVE-2025-59572HIGH
Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Cross Site Request Forgery.This issue affects WorkScout-Core: from n/a through <
Sep 22, 20258.827NONO
CVE-2025-2232CRITICAL
The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authentication bypass in all versions up to, and including, 1.2.8. T
Mar 14, 20259.827NONO
CVE-2026-52716MEDIUM
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
Jun 17, 20266.524NONO
CVE-2025-59571HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout-Core workscout-core allows Reflected XSS.This issue affec
Oct 22, 20257.123NONO
CVE-2021-24318MEDIUM
The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete a
Jun 1, 20216.522NONO
CVE-2021-24238MEDIUM
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any au
Apr 22, 20216.522NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
50%
42%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (33.3%)
Unknown0 (0.0%)
Required8 (66.7%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None9 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Purethemes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Purethemes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Purethemes's Products

View all 3 CNAs →

Top CWEs