Waspthemes develops a small portfolio of WordPress theme customization and CSS editing plugins, with a durable signal centered on client-side input-handling vulnerabilities including cross-site scripting and cross-site request forgery. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Waspthemes over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5984HIGH Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | Jul 5, 2019 | 8.8 | 28 | NO | NO |
CVE-2024-43963MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WaspThemes YellowPencil Visual CSS Style Editor allows Reflected XSS.Th | Aug 29, 2024 | 6.1 | 19 | NO | NO |
CVE-2022-33961MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WaspThemes Visual CSS Style Editor plugin <= 7.5.8 versions. | May 10, 2023 | 4.8 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Waspthemes.
Media articles that mention a CVE ID that affects a product developed by Waspthemes — matched by CVE ID, not by vendor name.