Themehunk develops WordPress plugins and builder extensions that extend content creation and form-handling capabilities, with a product portfolio spanning contact and lead-generation forms, popup builders, e-commerce functionality, and navigation menus. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, consistent with the widespread deployment and direct user-input exposure inherent to WordPress plugins. The exposure recurs across the vendor's plugin line through weakness classes including missing authorization, cross-site scripting, cross-site request forgery, PHP remote file inclusion, and information disclosure—all characteristic of web-application input handling and access-control weaknesses that expose WordPress sites to both authenticated and unauthenticated attack. Defenders running Themehunk plugins should treat security updates as a high-priority component of their WordPress maintenance cycle and monitor for exploitation of unpatched instances. Live severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themehunk over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11972CRITICAL The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary Hunk Comp | Dec 31, 2024 | 9.8 | 75 | NO | YES |
CVE-2024-9061CRITICAL The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJ | Oct 16, 2024 | 9.8 | 68 | NO | YES |
CVE-2024-9707CRITICAL The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST A | Oct 11, 2024 | 9.8 | 48 | NO | YES |
CVE-2026-56070CRITICAL Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. | Jun 26, 2026 | 9.3 | 36 | NO | NO |
CVE-2022-40218CRITICAL Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.1.4. | May 8, 2024 | 9.8 | 28 | NO | NO |
CVE-2026-25438HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks allows Reflected XSS.This issue af | Mar 19, 2026 | 7.1 | 25 | NO | NO |
CVE-2025-68046MEDIUM Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Retrieve E | Jan 22, 2026 | 6.5 | 25 | NO | NO |
CVE-2025-52816CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita zita allows PHP Local File Inclusion.This is | Jun 27, 2025 | 9.8 | 25 | NO | NO |
CVE-2023-27431HIGH Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk Big Store theme <= 1.9.3 versions. | Nov 12, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-38057CRITICAL Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.2.1. | Mar 25, 2024 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themehunk.
Media articles that mention a CVE ID that affects a product developed by Themehunk — matched by CVE ID, not by vendor name.