ThemeHigh has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 6.3 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Products
- Payment Gateway of Stripe for WooCommerce 1
- woo-extra-product-options 1
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-102392High· 7.2Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.40CVE-2026-9832Medium· 5.3The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.829
ThemeHigh vulnerabilities
CVEs affecting ThemeHigh, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-102392High· 7.2Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
▾ TwilightThemeHigh · woo-extra-product-optionsvia NVD
CVE-2026-9832Medium· 5.3The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_…
▾ Sunlitthemehigh · Payment Gateway of Stripe for WooCommerceEPSS 0.38%via NVD