Weavertheme's vulnerability footprint centers on a narrow set of WordPress theme and plugin products, including Weaver Xtreme Theme and related support and content-distribution extensions that serve site builders and content managers. The recurring weakness classes—cross-site scripting and deserialization of untrusted data—reflect the web-application input-handling and data-processing demands inherent to theme and plugin ecosystems. Defenders should track this vendor's releases within their WordPress security update cycle; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weavertheme over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4971HIGH The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege u | Oct 16, 2023 | 7.2 | 22 | NO | NO |
CVE-2023-1404MEDIUM The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 1 | Jun 9, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-1403MEDIUM The Weaver Xtreme Theme for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 5.0.7. | Jun 9, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0276MEDIUM The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the sho | Apr 24, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-4939MEDIUM The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and including, 6.4 due to in | Jun 5, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-6990MEDIUM The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions up to, and including, 6.3.0 due to insufficient input saniti | Jan 11, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weavertheme.
Media articles that mention a CVE ID that affects a product developed by Weavertheme — matched by CVE ID, not by vendor name.