Xtemos maintains a specialized WordPress theme and plugin ecosystem centered on its WoodMart product line, a niche portfolio that serves e-commerce site builders. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through web-application weakness classes including cross-site scripting, cross-site request forgery, unsafe deserialization, PHP remote file inclusion, and code injection—patterns endemic to dynamically interpreted and user-extensible WordPress environments. Defenders should treat WoodMart theme updates as a security priority for any WordPress installations relying on it, and verify access controls around customization and plugin configuration; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xtemos over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56072HIGH Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions. | Jun 26, 2026 | 7.1 | 29 | NO | NO |
CVE-2023-32242CRITICAL Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1 | Dec 21, 2023 | 9.8 | 26 | NO | NO |
CVE-2026-23971HIGH Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects WoodMart: from n/a through <= 8.3.8. | Mar 25, 2026 | 8.1 | 25 | NO | NO |
CVE-2025-47600MEDIUM Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in xtemos WoodMart woodmart allows Code Injection.This issue affects WoodMart: from n/a | Jan 22, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-49935HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart allows PHP Local File Inclusion.Th | Oct 22, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-6746HIGH The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authentic | Jul 8, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-49936MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart woodmart allows DOM-Based XSS.This issue affects WoodMart: fro | Oct 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-6744HIGH The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execu | Jul 8, 2025 | 7.3 | 21 | NO | NO |
CVE-2023-32500HIGH Cross-Site Request Forgery (CSRF) vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme <= 7.1.1 versions. | Nov 9, 2023 | 8.8 | 21 | NO | NO |
CVE-2025-8097MEDIUM The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient validation of the qty parameter | Jul 26, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xtemos.
Media articles that mention a CVE ID that affects a product developed by Xtemos — matched by CVE ID, not by vendor name.