Themekraft develops WordPress plugins focused on community engagement and e-commerce integration, particularly BuddyPress extensions and user-profile form builders that operate within the WordPress ecosystem. The vendor's vulnerability footprint, while concentrated in a small product portfolio, sits in a prominent position given the widespread adoption of WordPress and the plugins' role in handling user authentication, form submission, and content generation. Recurring weaknesses center on authorization and access-control gaps, cross-site scripting in form and page rendering, and improper handling of serialized data, which reflect both the complexity of integrating multiple third-party systems and the input-validation demands of user-facing form components. A meaningful share of the vendor's disclosures reach serious severity, reflecting the sensitivity of user account and data-handling operations in these plugins. Defenders deploying these plugins should prioritize patching and access-control hardening; current exploitation status and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themekraft over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26326CRITICAL The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issu | Feb 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2018-21003CRITICAL The buddyforms plugin before 2.2.8 for WordPress has SQL injection. | Aug 27, 2019 | 9.8 | 28 | NO | NO |
CVE-2024-8246HIGH The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in | Sep 14, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-35726HIGH Missing Authorization vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.19. | Jun 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-32151HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyforms allows PHP Local File Incl | Apr 4, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-32603HIGH Deserialization of Untrusted Data vulnerability in ThemeKraft WooBuddy.This issue affects WooBuddy: from n/a through 3.4.20. | Apr 18, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-5823HIGH Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions. | Nov 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-32830HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.Th | May 17, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-1169HIGH The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media uplo | Mar 7, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-1170HIGH The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media file | Mar 7, 2024 | 8.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themekraft.
Media articles that mention a CVE ID that affects a product developed by Themekraft — matched by CVE ID, not by vendor name.