Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Themehunk

First CVE: Dec 27, 2021Active for: 5 yearsTotal CVEs: 25
44.8
VTI Score
High

Themehunk develops WordPress plugins and builder extensions that extend content creation and form-handling capabilities, with a product portfolio spanning contact and lead-generation forms, popup builders, e-commerce functionality, and navigation menus. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, consistent with the widespread deployment and direct user-input exposure inherent to WordPress plugins. The exposure recurs across the vendor's plugin line through weakness classes including missing authorization, cross-site scripting, cross-site request forgery, PHP remote file inclusion, and information disclosure—all characteristic of web-application input handling and access-control weaknesses that expose WordPress sites to both authenticated and unauthenticated attack. Defenders running Themehunk plugins should treat security updates as a high-priority component of their WordPress maintenance cycle and monitor for exploitation of unpatched instances. Live severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Themehunk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2021
4 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-11972CRITICAL
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Comp
Dec 31, 20249.875NOYES
CVE-2024-9061CRITICAL
The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJ
Oct 16, 20249.868NOYES
CVE-2024-9707CRITICAL
The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST A
Oct 11, 20249.848NOYES
CVE-2026-56070CRITICAL
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
Jun 26, 20269.336NONO
CVE-2022-40218CRITICAL
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.1.4.
May 8, 20249.828NONO
CVE-2026-25438HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks allows Reflected XSS.This issue af
Mar 19, 20267.125NONO
CVE-2025-68046MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Retrieve E
Jan 22, 20266.525NONO
CVE-2025-52816CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita zita allows PHP Local File Inclusion.This is
Jun 27, 20259.825NONO
CVE-2023-27431HIGH
Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk Big Store theme <= 1.9.3 versions.
Nov 12, 20238.825NONO
CVE-2022-38057CRITICAL
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.2.1.
Mar 25, 20249.824NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
60%
12%
28%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (56.0%)
Unknown0 (0.0%)
Required11 (44.0%)
Privileges Required
Low8 (32.0%)
High2 (8.0%)
None15 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
12.0% of CVEs· 97th percentile
ExploitDB
1 CVE
4.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Themehunk.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Themehunk — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Themehunk's Products

View all 3 CNAs →

Top CWEs