Themify maintains a portfolio of WordPress themes and plugins, including its flagship Builder, Portfolio Post, Ultra theme, and WooCommerce Product Filter extensions, that serve content creators and small-business websites. The vendor's vulnerability profile centers on web-application-layer weaknesses endemic to WordPress ecosystem components: cross-site scripting and cross-site request forgery dominate the exposure, while file-upload handling, deserialization, and access-control issues recur across the product line. These weakness classes reflect the challenges of building extensible, user-facing WordPress functionality without introducing injection or privilege-boundary flaws. Defenders should apply Themify plugin and theme updates promptly, exercise caution with user-generated content permissions, and validate file-upload restrictions on affected WooCommerce integrations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themify over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-20002CRITICAL Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file. | Jun 17, 2021 | 9.8 | 32 | NO | NO |
CVE-2023-46149HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | Dec 20, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-46148HIGH Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | Jun 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-46146HIGH Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | Jun 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-3032MEDIUM Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue | Jun 13, 2024 | 6.1 | 26 | NO | YES |
CVE-2024-6027HIGH The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all versions up to, and including, 1.4.9 d | Jun 21, 2024 | 7.5 | 24 | NO | NO |
CVE-2023-46145HIGH Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5. | May 17, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-24872HIGH Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects Themify Builder: from n/a through 7.0.5. | Feb 21, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-46147HIGH Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | Dec 20, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-1532MEDIUM Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site | Jun 13, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themify.
Media articles that mention a CVE ID that affects a product developed by Themify — matched by CVE ID, not by vendor name.