Purethemes develops a focused line of WordPress-based themes and plugins for real estate, job marketplace, and service-listing applications, a niche portfolio that concentrates in web application and access-control attack surfaces. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, with recurring weaknesses including cross-site scripting, improper access control, authorization bypass, and privilege management flaws that are characteristic of WordPress-adjacent web applications. Defenders deploying these themes should prioritize tracking updates and restricting administrative access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Purethemes over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57786HIGH Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7. | Jul 13, 2026 | 8.8 | 35 | NO | NO |
CVE-2021-24237MEDIUM The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before out | Apr 22, 2021 | 6.1 | 31 | NO | YES |
CVE-2025-67960HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout-Core workscout-core allows Reflected XSS.This issue affec | Jan 22, 2026 | 7.1 | 27 | NO | NO |
CVE-2025-67959HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout workscout allows Reflected XSS.This issue affects WorkSco | Jan 22, 2026 | 7.1 | 27 | NO | NO |
CVE-2025-59572HIGH Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Cross Site Request Forgery.This issue affects WorkScout-Core: from n/a through < | Sep 22, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-2232CRITICAL The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authentication bypass in all versions up to, and including, 1.2.8. T | Mar 14, 2025 | 9.8 | 27 | NO | NO |
CVE-2026-52716MEDIUM Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions. | Jun 17, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-59571HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout-Core workscout-core allows Reflected XSS.This issue affec | Oct 22, 2025 | 7.1 | 23 | NO | NO |
CVE-2021-24318MEDIUM The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete a | Jun 1, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-24238MEDIUM The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any au | Apr 22, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Purethemes.
Media articles that mention a CVE ID that affects a product developed by Purethemes — matched by CVE ID, not by vendor name.