Radiustheme develops a portfolio of WordPress plugins and themes for content display, listing management, and team showcase functionality. The vendor's vulnerability footprint concentrates in web-application-layer weaknesses across its recurring products including Classified Listing, The Post Grid, and Team WordPress Member Showcase plugins, with exposure dominated by cross-site scripting, cross-site request forgery, and authorization issues that are characteristic of plugin input-handling and capability-checking gaps. These weakness classes reflect the common challenge of securing user-generated content, form submission, and administrative feature access in WordPress ecosystems. Defenders should apply plugin updates from this vendor promptly and audit permission configurations, particularly for publicly accessible listing and form submission functionality; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Radiustheme over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57355MEDIUM Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions. | Jul 2, 2026 | 6.5 | 33 | NO | NO |
CVE-2026-57344HIGH Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions. | Jul 2, 2026 | 7.1 | 29 | NO | NO |
CVE-2022-2557HIGH The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermor | Aug 22, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-46853HIGH Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 5.0.4 versions. | May 23, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-53565HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Widget for Google Reviews business-reviews-wp a | Aug 20, 2025 | 8.1 | 26 | NO | NO |
CVE-2023-37387HIGH Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions. | Jul 18, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-7327HIGH The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. This makes it possibl | Jul 8, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-37520HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Add | Jul 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-1315HIGH The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. Th | Apr 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-39923HIGH Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 7.2.7 versions. | Oct 3, 2023 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Radiustheme.
Media articles that mention a CVE ID that affects a product developed by Radiustheme — matched by CVE ID, not by vendor name.