Theme4press develops a narrow portfolio of WordPress themes, including Demo Awesome and Evolve, that extend the presentation and functionality of WordPress sites. The durable signal in this vendor's disclosures centers on web-layer input-handling weaknesses, specifically cross-site scripting vulnerabilities arising from improper neutralization of user input during page generation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Theme4press over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3852MEDIUM Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. | Sep 28, 2011 | 4.3 | 25 | NO | YES |
CVE-2024-37206MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme4Press Demo Awesome allows Reflected XSS.This issue affects Demo A | Jul 22, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-37207MEDIUM Missing Authorization vulnerability in Theme4Press Demo Awesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Awesome: from n/a th | Nov 1, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Theme4press.
Media articles that mention a CVE ID that affects a product developed by Theme4press — matched by CVE ID, not by vendor name.