Themeworm maintains a narrowly scoped WordPress extension, Plexx Elementor, that extends page-building functionality for site customization. The durable signal in its disclosed vulnerabilities centers on improper input neutralization during web page generation, a class of flaw endemic to content-rendering plugins where user-controlled data flows into the DOM without sufficient sanitization. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themeworm over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-49234MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeworm Plexx Elementor Extension plexx-elementor-extension allows DOM-Based | Oct 18, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themeworm.
Media articles that mention a CVE ID that affects a product developed by Themeworm — matched by CVE ID, not by vendor name.