Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Themepunch

First CVE: Jun 30, 2015Active for: 11 yearsTotal CVEs: 17
43.2
VTI Score
High

Themepunch develops WordPress plugins and themes such as Slider Revolution, ShowBiz Pro, and Essential Grid that are widely deployed across WordPress sites, placing them in a prominent position within the web-publishing ecosystem. Vulnerabilities affecting the vendor's products skew toward moderate-to-serious outcomes and frequently acquire public exploit code, clustering around web-application weaknesses including cross-site scripting, unrestricted file uploads, deserialization flaws, code injection, and path traversal that are characteristic of server-side PHP processing and user-input handling in plugin contexts. Defenders should prioritize updates for these popular plugins and monitor for exploitation attempts targeting their attack surface; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Themepunch over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 30, 2015
11 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-9735HIGH
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administ
Jun 30, 20157.584NOYES
CVE-2015-9499CRITICAL
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
Oct 22, 20199.848NOYES
CVE-2014-9734MEDIUM
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img
Jun 30, 20155.031NOYES
CVE-2026-57678HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider
Jul 2, 20267.129NONO
CVE-2023-47684MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions.
Nov 14, 20236.128NOYES
CVE-2023-2359HIGH
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Ex
Jun 19, 20238.826NONO
CVE-2024-34444HIGH
Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.
Jun 19, 20248.825NONO
CVE-2023-6528HIGH
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially l
Jan 8, 20248.825NONO
CVE-2023-47784HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.
Dec 20, 20238.823NONO
CVE-2024-34443MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects S
Jun 19, 20245.418NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
59%
35%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (82.4%)
Unknown3 (17.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (82.4%)
High0 (0.0%)
Unknown3 (17.6%)
User Interaction
None4 (23.5%)
Unknown3 (17.6%)
Required10 (58.8%)
Privileges Required
Low9 (52.9%)
High1 (5.9%)
None4 (23.5%)
Unknown3 (17.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.9% of CVEs· 98th percentile
Nuclei
3 CVEs
17.6% of CVEs· 97th percentile
ExploitDB
2 CVEs
11.8% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Themepunch.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Themepunch — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Themepunch's Products

View all 4 CNAs →

Top CWEs