Xplodedthemes develops a modestly represented portfolio of WordPress-focused plugins and tools, including the WPIDE file manager and code editor alongside e-commerce add-ons for WooCommerce. The vendor's vulnerability exposure centers on path-traversal and cross-site scripting flaws, alongside issues involving sensitive information disclosure and unauthorized access to files or directories—weakness classes typical of web-facing PHP plugins where input validation and access control are frequently underspecified. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xplodedthemes over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40217HIGH Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. | Sep 21, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-2261HIGH The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File I | Aug 29, 2022 | 7.2 | 23 | NO | NO |
CVE-2024-8716MEDIUM The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL | Sep 24, 2024 | 6.1 | 18 | NO | NO |
CVE-2022-35235MEDIUM Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. | Aug 23, 2022 | 4.9 | 18 | NO | NO |
CVE-2024-9178MEDIUM The XT Floating Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.8.2 due to insuf | Nov 5, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-9546MEDIUM The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing t | Oct 15, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xplodedthemes.
Media articles that mention a CVE ID that affects a product developed by Xplodedthemes — matched by CVE ID, not by vendor name.