Themeeditor is a niche vendor centered on a theme-editing application with a focused vulnerability footprint characterized by structural input-handling and access-control weaknesses such as untrusted deserialization and exposure of files or directories to external parties. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themeeditor over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2440HIGH The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possi | Aug 29, 2024 | 7.2 | 24 | NO | NO |
CVE-2021-24154MEDIUM The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrar | Apr 5, 2021 | 4.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themeeditor.
Media articles that mention a CVE ID that affects a product developed by Themeeditor — matched by CVE ID, not by vendor name.