Spider Themes develops a small set of WordPress plugins, notably EazyDocs and BBP Core, that extend document management and forum functionality within the WordPress ecosystem. The vendor's vulnerability profile reflects the typical input-handling and access-control risks inherent to WordPress plugin development, though the exposure remains modest in scope and focused to the plugin layer rather than core platform issues. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spider Themes over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68572HIGH Missing Authorization vulnerability in Spider Themes BBP Core bbp-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BBP Core: from n/a | Dec 24, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-6035HIGH The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any auth | Dec 11, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-6029HIGH The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing | Jan 15, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-47648HIGH Missing Authorization vulnerability in Spider Themes EazyDocs eazydocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a | Jan 2, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-54376HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider Themes EazyDocs eazydocs allows PHP Local File Inclu | Dec 16, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-38721HIGH Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through | Nov 1, 2024 | 7.1 | 20 | NO | NO |
CVE-2024-38720MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EazyDocs eazydocs allows Stored XSS.This issue affects EazyDocs: from n | Jul 20, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-9896MEDIUM The BBP Core – Expand bbPress powered forums with useful features plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appro | Nov 2, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-47549MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.3 versions. | Nov 14, 2023 | 6.1 | 18 | NO | NO |
CVE-2025-32221MEDIUM Missing Authorization vulnerability in Spider Themes EazyDocs eazydocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a | Apr 10, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spider Themes.
Media articles that mention a CVE ID that affects a product developed by Spider Themes — matched by CVE ID, not by vendor name.