Themeinprogress develops a narrow portfolio of web-application and e-commerce products—including custom login systems, marketplace themes, and storefront platforms—that share a consistent exposure to client-side and server-side input-handling vulnerabilities. The durable signal across its disclosures centers on cross-site request forgery, cross-site scripting, and missing authorization controls, weakness classes typical of web applications where request validation and access enforcement demand careful design. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themeinprogress over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-17362MEDIUM search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS. | Aug 12, 2020 | 6.1 | 31 | NO | YES |
CVE-2023-2813MEDIUM All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business | Sep 4, 2023 | 6.1 | 25 | NO | YES |
CVE-2023-33313HIGH Cross-Site Request Forgery (CSRF) vulnerability in ThemeinProgress WIP Custom Login plugin <= 1.2.9 versions. | May 28, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-42884HIGH Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7. | Jan 17, 2024 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themeinprogress.
Media articles that mention a CVE ID that affects a product developed by Themeinprogress — matched by CVE ID, not by vendor name.