Themepunch develops WordPress plugins and themes such as Slider Revolution, ShowBiz Pro, and Essential Grid that are widely deployed across WordPress sites, placing them in a prominent position within the web-publishing ecosystem. Vulnerabilities affecting the vendor's products skew toward moderate-to-serious outcomes and frequently acquire public exploit code, clustering around web-application weaknesses including cross-site scripting, unrestricted file uploads, deserialization flaws, code injection, and path traversal that are characteristic of server-side PHP processing and user-input handling in plugin contexts. Defenders should prioritize updates for these popular plugins and monitor for exploitation attempts targeting their attack surface; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themepunch over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9735HIGH The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administ | Jun 30, 2015 | 7.5 | 84 | NO | YES |
CVE-2015-9499CRITICAL The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive. | Oct 22, 2019 | 9.8 | 48 | NO | YES |
CVE-2014-9734MEDIUM Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img | Jun 30, 2015 | 5.0 | 31 | NO | YES |
CVE-2026-57678HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS.
This issue affects Slider | Jul 2, 2026 | 7.1 | 29 | NO | NO |
CVE-2023-47684MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions. | Nov 14, 2023 | 6.1 | 28 | NO | YES |
CVE-2023-2359HIGH The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Ex | Jun 19, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-34444HIGH Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0. | Jun 19, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-6528HIGH The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially l | Jan 8, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-47784HIGH Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15. | Dec 20, 2023 | 8.8 | 23 | NO | NO |
CVE-2024-34443MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects S | Jun 19, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themepunch.
Media articles that mention a CVE ID that affects a product developed by Themepunch — matched by CVE ID, not by vendor name.