Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sktthemes

First CVE: Feb 29, 2024Active for: 2 yearsTotal CVEs: 18
7.2
VTI Score
Low

SKTThemes develops WordPress themes and plugins such as SKT Blocks, SKT Addons for Elementor, and SKT Templates, which serve content creators and website builders. The vendor's vulnerability profile centers on application-layer issues recurring across its product line, including cross-site scripting, authorization bypass, cross-site request forgery, and missing authorization checks, which are characteristic of web-facing customization and management interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sktthemes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 29, 2024
2 years ago
Most Recent CVE
May 19, 2025
432 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-46243HIGH
Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abandoned-cart allows Cross Site Request Forgery.This issue affect
Apr 22, 20258.824NONO
CVE-2025-26998MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Bl
Apr 15, 20255.419NONO
CVE-2024-5091MEDIUM
The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Age Gate and Creative Slider widgets in all versions up to, and incl
Jun 8, 20245.419NONO
CVE-2025-3276MEDIUM
The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Carousel block in all versions up to, and including, 1.
Apr 12, 20255.418NONO
CVE-2024-44007MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Templates – Elementor & Gutenberg templates skt-templates all
Sep 17, 20246.118NONO
CVE-2024-43946MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes SKT Blocks – Gutenberg based Page Builder allows Stored XSS.
Aug 29, 20245.418NONO
CVE-2024-34445MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT A
May 14, 20245.418NONO
CVE-2024-1337MEDIUM
The SKT Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saveSktbuilderPageData' function in all versi
Feb 29, 20244.318NONO
CVE-2025-48270MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows DOM-Based XSS.This issue affects SKT
May 19, 20255.417NONO
CVE-2025-46235MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Bl
Apr 22, 20255.417NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
94%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (11.1%)
Unknown0 (0.0%)
Required16 (88.9%)
Privileges Required
Low16 (88.9%)
High0 (0.0%)
None2 (11.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sktthemes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sktthemes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sktthemes's Products

View all 2 CNAs →

Top CWEs