Themehorse develops a focused portfolio of WordPress themes and plugins—including Clean Retina, Interface, Mags, Meta News, and Newscard—that target content publishing and news-aggregation use cases. The vendor's vulnerability exposure centers on web-application input-handling weaknesses, principally PHP remote file inclusion and cross-site scripting flaws that are endemic to template and plugin architectures handling user-supplied content and third-party data sources. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themehorse over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-50436HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Clean Retina clean-retina.This issue affects Cle | Oct 28, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-50435HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Meta News meta-news.This issue affects Meta News | Oct 28, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-50434HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse NewsCard newscard.This issue affects NewsCard: f | Oct 28, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-49701HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Mags mags.This issue affects Mags: from n/a thro | Oct 23, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-33537MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Horse WP Portfolio allows Stored XSS.This issue affects WP Portfolio: fr | Apr 29, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-35758MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Horse Interface allows Stored XSS.This issue affects Interface: f | Jun 21, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themehorse.
Media articles that mention a CVE ID that affects a product developed by Themehorse — matched by CVE ID, not by vendor name.