Themewinter develops a focused portfolio of WordPress plugins, including EventIn and WPCafe, that extend e-commerce and event-management functionality for small-to-medium web properties. Despite a narrow product scope, these plugins occupy a prominent position in the WordPress ecosystem, where widespread installation and often-delayed updates create high-value targets. Vulnerabilities affecting this vendor skew toward serious outcomes and acquire public exploit code at a notable rate, concentrating in web-layer weaknesses such as path traversal, missing authorization checks, cross-site scripting, PHP remote file inclusion, and authorization bypass through user-controlled keys—flaws characteristic of plugin development under time-to-market pressure. Defenders should monitor Themewinter's release cycles closely and audit their WordPress installations for these plugins; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themewinter over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47539CRITICAL Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26. | May 23, 2025 | 9.8 | 57 | NO | YES |
CVE-2025-47445CRITICAL Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26. | May 14, 2025 | 9.8 | 39 | NO | YES |
CVE-2025-4796HIGH The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly val | Aug 8, 2025 | 8.8 | 29 | NO | NO |
CVE-2024-7149HIGH The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via mult | Sep 27, 2024 | 8.8 | 26 | NO | NO |
CVE-2025-1770HIGH The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.24 via the | Mar 20, 2025 | 8.8 | 25 | NO | NO |
CVE-2023-47805CRITICAL Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through | Dec 9, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-43135HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n | Aug 13, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-37513HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows Path Traversal.This issue affects WPCafe: from n/a through | Jul 9, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-56213HIGH Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.7. | Dec 31, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-5431HIGH The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and | Jun 25, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themewinter.
Media articles that mention a CVE ID that affects a product developed by Themewinter — matched by CVE ID, not by vendor name.