VulnSea

themeum has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 8. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (3). Most affected products: Tutor LMS – eLearning and online course solution (4), WP Crowdfunding (2), Kirki – Freeform Page Builder, Website Builder & Customizer (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
8 prev 0

Products

  • Tutor LMS – eLearning and online course solution 4
  • WP Crowdfunding 2
  • Kirki – Freeform Page Builder, Website Builder & Customizer 1
  • wp-megamenu 1
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

themeum vulnerabilities

CVEs affecting themeum, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-89333Medium· 6.5
2d ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.27%via NVD
CVE-2026-89081Medium· 6.1
2d ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and o…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and o…

Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.21%via NVD
CVE-2026-88944Medium· 4.3
2d ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. This is due to the plugin not properly verifying that a user is authorized to pe…

Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.28%via NVD
CVE-2026-92465High· 7.6
5d ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

TwilightThemeum · wp-megamenuEPSS 0.30%via NVD
CVE-2026-78175High· 8.8
1w ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJ…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJ…

Twilightthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.59%via NVD
CVE-2026-17037High· 7.2
1w ago

Kirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘comment’ parameter in all versions up to, and including, 6.2.0 due to insufficient input sanitizat…

Twilightthemeum · Kirki – Freeform Page Builder, Website Builder & CustomizerEPSS 0.30%via CVEORG
CVE-2026-19945Medium· 6.4
1w ago

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it po…

Sunlitthemeum · WP CrowdfundingEPSS 0.22%via NVD
CVE-2026-19944Medium· 4.9
1w ago

The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient p…

The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient p…

Sunlitthemeum · WP CrowdfundingEPSS 0.27%via NVD
themeum vulnerabilities (CVEs) · VulnSea