Themeisle has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.3 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO 1
- Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE 1
- multiple-pages-generator-by-porthas 1
Worst active — by depth score
CVE-2026-85198Medium· 6.5The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user suppli…36CVE-2026-97302Medium· 5.3Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.29CVE-2026-4945Medium· 5.3The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to miss…29
Themeisle vulnerabilities
CVEs affecting Themeisle, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-97302Medium· 5.3Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
CVE-2026-85198Medium· 6.5The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user suppli…
The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user suppli…
CVE-2026-4945Medium· 5.3The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to miss…
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to miss…