Themeisle develops a focused set of WordPress plugins and themes, including Orbit Fox, Otter Blocks, Multiple Page Generator, RSS Aggregator by Feedzy, and Visualizer, that extend functionality for website builders and content management. Though concentrated in a narrow product portfolio, these components enjoy prominent deployment across WordPress ecosystems, making the vendor's vulnerability profile relevant to a broad base of deployed sites. The exposure recurs consistently through web-application weakness classes—cross-site scripting, CSRF, missing authorization, SQL injection, and server-side request forgery—that are characteristic of plugin-oriented PHP codebases handling user input and site configuration. These classes reflect the tension between feature richness and input validation in community-contributed WordPress extensions, and defenders should treat updates to these plugins as part of their routine WordPress hardening. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themeisle over time
Signals from CVEs in this vendor scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16932CRITICAL A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data. | Sep 30, 2019 | 10.0 | 63 | NO | YES |
CVE-2023-2288HIGH The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerabil | May 30, 2023 | 8.8 | 34 | NO | NO |
CVE-2026-65526HIGH Contributor SQL Injection in Visualizer <= 4.0.6 versions. | Jul 23, 2026 | 8.5 | 32 | NO | NO |
CVE-2019-16931MEDIUM A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user ed | Oct 3, 2019 | 6.1 | 32 | NO | YES |
CVE-2023-2256MEDIUM The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting. | May 30, 2023 | 6.1 | 29 | NO | YES |
CVE-2022-2444HIGH The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrusted input via the 'remote_data' parameter in versions up to, | Jul 18, 2022 | 8.8 | 29 | NO | NO |
CVE-2024-35736HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visualizer: from n/a through 3.11.1. | Jun 8, 2024 | 8.8 | 26 | NO | NO |
CVE-2022-47143HIGH Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions. | Mar 14, 2023 | 8.8 | 26 | NO | NO |
CVE-2026-24573MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS.
This issue affects Visualizer: from n | May 20, 2026 | 6.5 | 25 | NO | NO |
CVE-2024-47325HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle MPG multiple-pages-generator-by-porthas allows SQL Injection.This is | Oct 20, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (63 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themeisle.
Media articles that mention a CVE ID that affects a product developed by Themeisle — matched by CVE ID, not by vendor name.