Villatheme develops a focused suite of e-commerce plugins and extensions for WooCommerce, including tools for order tracking, cart functionality, product customization, and fulfillment workflows. Its vulnerability footprint clusters around web-application input-handling and access-control weaknesses—cross-site request forgery, cross-site scripting, missing authorization, and authentication bypass—that are characteristic of WordPress plugin ecosystems where enforcement of output encoding and permission checks varies widely across third-party code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Villatheme over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57698MEDIUM Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse | Jul 13, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-2019HIGH The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.1.21. This is due to insufficient input validation | Feb 18, 2026 | 7.2 | 29 | NO | NO |
CVE-2024-8277CRITICAL The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not prop | Sep 11, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-46812HIGH Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin <= 1.0.13 versions. | May 25, 2023 | 8.8 | 26 | NO | NO |
CVE-2025-68550HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky wpbulky-wp-bulk-edit-post-types allows Blind SQL Injection. | Dec 23, 2025 | 7.6 | 25 | NO | NO |
CVE-2022-46810HIGH Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Thank You Page Customizer for WooCommerce – Increase Your Sales plugin <= 1.0.13 versions. | May 25, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-41623HIGH Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress. | Oct 14, 2022 | 7.5 | 24 | NO | NO |
CVE-2024-13320HIGH The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the 'wc_filter_price_meta[where]' parameter in all versions up to | Mar 7, 2025 | 7.5 | 22 | NO | NO |
CVE-2023-48778HIGH Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Product Size Chart For WooCommerce.This issue affects Product Size Chart For WooCommerce: from n/a through 1.1.5. | Dec 18, 2023 | 8.8 | 21 | NO | NO |
CVE-2021-4379MEDIUM The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmc_bulk_fixed_price function in versions up to, | Jun 7, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Villatheme.
Media articles that mention a CVE ID that affects a product developed by Villatheme — matched by CVE ID, not by vendor name.