Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Themeisle

First CVE: Sep 30, 2019Active for: 7 yearsTotal CVEs: 63
27.9
VTI Score
Low

Themeisle develops a focused set of WordPress plugins and themes, including Orbit Fox, Otter Blocks, Multiple Page Generator, RSS Aggregator by Feedzy, and Visualizer, that extend functionality for website builders and content management. Though concentrated in a narrow product portfolio, these components enjoy prominent deployment across WordPress ecosystems, making the vendor's vulnerability profile relevant to a broad base of deployed sites. The exposure recurs consistently through web-application weakness classes—cross-site scripting, CSRF, missing authorization, SQL injection, and server-side request forgery—that are characteristic of plugin-oriented PHP codebases handling user input and site configuration. These classes reflect the tension between feature richness and input validation in community-contributed WordPress extensions, and defenders should treat updates to these plugins as part of their routine WordPress hardening. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
63
Total CVEs
More Total CVEs than 99% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Themeisle over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 30, 2019
6 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (63 CVEs).

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-16932CRITICAL
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
Sep 30, 201910.063NOYES
CVE-2023-2288HIGH
The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerabil
May 30, 20238.834NONO
CVE-2026-65526HIGH
Contributor SQL Injection in Visualizer <= 4.0.6 versions.
Jul 23, 20268.532NONO
CVE-2019-16931MEDIUM
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user ed
Oct 3, 20196.132NOYES
CVE-2023-2256MEDIUM
The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.
May 30, 20236.129NOYES
CVE-2022-2444HIGH
The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data' parameter in versions up to,
Jul 18, 20228.829NONO
CVE-2024-35736HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visualizer: from n/a through 3.11.1.
Jun 8, 20248.826NONO
CVE-2022-47143HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions.
Mar 14, 20238.826NONO
CVE-2026-24573MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n
May 20, 20266.525NONO
CVE-2024-47325HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle MPG multiple-pages-generator-by-porthas allows SQL Injection.This is
Oct 20, 20248.825NONO
View all 63 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products63 CVEs
71%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network63 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None26 (41.3%)
Unknown0 (0.0%)
Required37 (58.7%)
Privileges Required
Low40 (63.5%)
High4 (6.3%)
None19 (30.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.8% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Themeisle.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Themeisle — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Themeisle's Products

View all 4 CNAs →

Top CWEs