Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Villatheme

First CVE: Jan 24, 2022Active for: 4 yearsTotal CVEs: 23
22.1
VTI Score
Low

Villatheme develops a focused suite of e-commerce plugins and extensions for WooCommerce, including tools for order tracking, cart functionality, product customization, and fulfillment workflows. Its vulnerability footprint clusters around web-application input-handling and access-control weaknesses—cross-site request forgery, cross-site scripting, missing authorization, and authentication bypass—that are characteristic of WordPress plugin ecosystems where enforcement of output encoding and permission checks varies widely across third-party code. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Villatheme over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2022
4 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-57698MEDIUM
Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse
Jul 13, 20266.529NONO
CVE-2026-2019HIGH
The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.1.21. This is due to insufficient input validation
Feb 18, 20267.229NONO
CVE-2024-8277CRITICAL
The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not prop
Sep 11, 20249.829NONO
CVE-2022-46812HIGH
Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin <= 1.0.13 versions.
May 25, 20238.826NONO
CVE-2025-68550HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky wpbulky-wp-bulk-edit-post-types allows Blind SQL Injection.
Dec 23, 20257.625NONO
CVE-2022-46810HIGH
Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin <= 1.0.13 versions.
May 25, 20238.825NONO
CVE-2022-41623HIGH
Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress.
Oct 14, 20227.524NONO
CVE-2024-13320HIGH
The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the 'wc_filter_price_meta[where]' parameter in all versions up to
Mar 7, 20257.522NONO
CVE-2023-48778HIGH
Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Product Size Chart For WooCommerce.This issue affects Product Size Chart For WooCommerce: from n/a through 1.1.5.
Dec 18, 20238.821NONO
CVE-2021-4379MEDIUM
The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmc_bulk_fixed_price function in versions up to,
Jun 7, 20236.521NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
57%
35%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (60.9%)
Unknown0 (0.0%)
Required9 (39.1%)
Privileges Required
Low6 (26.1%)
High6 (26.1%)
None11 (47.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Villatheme.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Villatheme — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Villatheme's Products

View all 3 CNAs →

Top CWEs