villatheme has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 4. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The most common weakness class is CWE-862 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 7 prev 0
Products
- Photo Reviews for WooCommerce 1
- affi-affiliate-marketing-for-woo 1
- woo-multi-currency 1
- woo-notification 1
- woo-photo-reviews 1
- woo-product-builder 1
Worst active — by depth score
CVE-2026-102379High· 8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue aff…47CVE-2026-101923High· 8.1The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.3045CVE-2026-100517High· 7.5Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.41CVE-2026-81786High· 7.5WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Control vulnerability41CVE-2026-94171High· 7.1Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.39
villatheme vulnerabilities
CVEs affecting villatheme, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-101923High· 8.1The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id par…
CVE-2026-100517High· 7.5Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.
CVE-2026-102390Medium· 5.3Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Mar…
Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Mar…
CVE-2026-102379High· 8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue aff…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue aff…
CVE-2026-94171High· 7.1Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.
Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.
CVE-2026-97261Medium· 5.3Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
CVE-2026-81786High· 7.5WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.