Themegrill develops a portfolio of WordPress themes and plugins serving educational and content management use cases, with its products appearing across many WordPress-powered sites. The vendor's disclosures skew toward serious outcomes and frequently acquire public exploit code, while the recurring weakness classes center on web-application input handling, access control, and authentication logic—common vectors in theme and plugin code that processes user input and manages administrative permissions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themegrill over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36333CRITICAL themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook. | May 5, 2021 | 9.1 | 41 | NO | YES |
CVE-2024-24882CRITICAL Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2. | May 17, 2024 | 9.8 | 39 | NO | YES |
CVE-2020-36837CRITICAL The ThemeGrill Demo Importer plugin for WordPress is vulnerable to authentication bypass due to a missing capability check on the reset_wizard_actions function in versions 1.3.4 th | Oct 16, 2024 | 9.9 | 29 | NO | NO |
CVE-2023-3345MEDIUM The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email a | Jul 31, 2023 | 6.5 | 26 | NO | YES |
CVE-2024-33939MEDIUM Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through | May 19, 2025 | 5.3 | 25 | NO | YES |
CVE-2020-36334HIGH themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database. | May 5, 2021 | 8.8 | 25 | NO | NO |
CVE-2024-0679MEDIUM The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and includin | Jan 20, 2024 | 6.5 | 21 | NO | NO |
CVE-2026-40730MEDIUM Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This iss | Apr 15, 2026 | 5.3 | 20 | NO | NO |
CVE-2024-37432MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Esteem allows Stored XSS.This issue affects Esteem: from n/a | Jul 22, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-9218MEDIUM The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scri | Oct 2, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themegrill.
Media articles that mention a CVE ID that affects a product developed by Themegrill — matched by CVE ID, not by vendor name.