Xylusthemes develops a suite of WordPress plugins focused on event management and data import functionality, including products such as WP Smart Import, WP Event Aggregator, WP Bulk Delete, and related event-widget components that extend WordPress's content capabilities. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through web-application weakness classes including cross-site scripting, PHP remote file inclusion, cross-site request forgery, missing authorization checks, and server-side request forgery—patterns characteristic of plugin-level input handling and access control in WordPress environments. Defenders should assess WordPress instances running these plugins and prioritize patches for the plugin tier; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xylusthemes over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24147CRITICAL Server-side request forgery (SSR) vulnerability in the WP Smart Import (wp-smart-import) plugin 1.0.0 for WordPress via the file field. | Jul 7, 2021 | 9.1 | 26 | NO | NO |
CVE-2025-47453CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes WP Smart Import wp-smart-import allows PHP Loc | May 23, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-47531HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Social Events xt-facebook- | May 7, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-47352HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WP Bulk Delete wp-bulk-delete allows Stored XSS.This issue affect | Oct 6, 2024 | 7.1 | 21 | NO | NO |
CVE-2022-40209MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xylus Themes WP Smart Import plugin <= 1.0.2 on WordPress. | Dec 6, 2022 | 6.1 | 21 | NO | NO |
CVE-2025-58192MEDIUM Missing Authorization vulnerability in Xylus Themes WP Bulk Delete wp-bulk-delete allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bulk | Aug 27, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-24700MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WP Event Aggregator wp-event-aggregator allows Reflected XSS.This | Feb 14, 2025 | 6.1 | 20 | NO | NO |
CVE-2024-38703MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xylus Themes WP Event Aggregator allows Stored XSS.This issue affects W | Jul 20, 2024 | 6.5 | 19 | NO | NO |
CVE-2025-48256MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes Import Social Events import-facebook-events allows Stored XSS.Thi | May 19, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-30201MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WordPress Importer allows Reflected XSS.This issue affects WordPr | Mar 27, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xylusthemes.
Media articles that mention a CVE ID that affects a product developed by Xylusthemes — matched by CVE ID, not by vendor name.