{"schema_version":1,"title":"Themeisle vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 21 vulnerabilities in Themeisle: 0 in the last 7 days and 11 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86784, was published on 16 September 2026. 3 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/themeisle","json_url":"https://junglewise.ai/threats/vendors/themeisle.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/themeisle","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":21,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":11,"last_365_days":21},"latest":[{"cve":"CVE-2026-86784","cvss":6.8,"epss":0.0043,"slug":"cve-2026-86784-visualizer-wordpress-plugin-stored-xss-in-json-data-source","title":"Visualizer WordPress plugin stored XSS in JSON data source","severity":"medium","exploited":false,"published_at":"2026-09-16T06:16:34.95+00:00","url":"https://junglewise.ai/threats/cve-2026-86784-visualizer-wordpress-plugin-stored-xss-in-json-data-source"},{"cve":"CVE-2026-85418","cvss":5.4,"epss":0.0023,"slug":"cve-2026-85418-orbit-fox-wordpress-plugin-stored-xss-in-beaver-builder-widget","title":"Orbit Fox WordPress plugin stored XSS in Beaver Builder widget","severity":"medium","exploited":false,"published_at":"2026-09-09T06:17:18.593+00:00","url":"https://junglewise.ai/threats/cve-2026-85418-orbit-fox-wordpress-plugin-stored-xss-in-beaver-builder-widget"},{"cve":"CVE-2026-78285","cvss":8.5,"epss":0.0036,"slug":"cve-2026-78285-like-button-rating-sql-injection","title":"Like Button Rating SQL injection","severity":"high","exploited":false,"published_at":"2026-08-27T10:16:38.01+00:00","url":"https://junglewise.ai/threats/cve-2026-78285-like-button-rating-sql-injection"},{"cve":"CVE-2026-66437","cvss":4.9,"slug":"cve-2026-66437-themeisle-feedzy-rss-feeds-ssrf-in-wordpress-plugin","title":"Themeisle Feedzy RSS Feeds SSRF in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-07-27T15:17:11.19+00:00","url":"https://junglewise.ai/threats/cve-2026-66437-themeisle-feedzy-rss-feeds-ssrf-in-wordpress-plugin"},{"cve":"CVE-2026-65563","cvss":5.9,"slug":"cve-2026-65563-themeisle-orbit-fox-cross-site-scripting","title":"ThemeIsle Orbit Fox Cross Site Scripting","severity":"medium","exploited":false,"published_at":"2026-07-27T15:17:09.657+00:00","url":"https://junglewise.ai/threats/cve-2026-65563-themeisle-orbit-fox-cross-site-scripting"},{"cve":"CVE-2026-15653","cvss":6.4,"slug":"cve-2026-15653-themeisle-visualizer-stored-xss-in-backend-title-parameter","title":"ThemeIsle Visualizer Stored XSS in backend-title parameter","severity":"medium","exploited":false,"published_at":"2026-07-24T08:16:26.28+00:00","url":"https://junglewise.ai/threats/cve-2026-15653-themeisle-visualizer-stored-xss-in-backend-title-parameter"},{"cve":"CVE-2026-65537","cvss":4.3,"slug":"cve-2026-65537-themeisle-cyr-to-lat-reloaded-broken-access-control","title":"Themeisle Cyr to Lat reloaded broken access control","severity":"medium","exploited":false,"published_at":"2026-07-23T12:18:46.737+00:00","url":"https://junglewise.ai/threats/cve-2026-65537-themeisle-cyr-to-lat-reloaded-broken-access-control"},{"cve":"CVE-2026-65526","cvss":8.5,"slug":"cve-2026-65526-themeisle-visualizer-sql-injection-in-wordpress-plugin","title":"Themeisle Visualizer SQL injection in WordPress plugin","severity":"high","exploited":false,"published_at":"2026-07-23T12:18:45.393+00:00","url":"https://junglewise.ai/threats/cve-2026-65526-themeisle-visualizer-sql-injection-in-wordpress-plugin"},{"cve":"CVE-2026-61970","cvss":4.9,"slug":"cve-2026-61970-themeisle-auto-featured-image-ssrf-in-auto-post-thumbnail","title":"Themeisle Auto Featured Image SSRF in auto-post-thumbnail","severity":"medium","exploited":false,"published_at":"2026-07-13T10:16:46.923+00:00","url":"https://junglewise.ai/threats/cve-2026-61970-themeisle-auto-featured-image-ssrf-in-auto-post-thumbnail"},{"cve":"CVE-2026-13252","cvss":6.4,"slug":"cve-2026-13252-themeisle-feedzy-rss-aggregator-stored-xss-via-aspectratio","title":"ThemeIsle Feedzy RSS Aggregator Stored XSS via aspectRatio attribute","severity":"medium","exploited":false,"published_at":"2026-07-02T10:16:28.01+00:00","url":"https://junglewise.ai/threats/cve-2026-13252-themeisle-feedzy-rss-aggregator-stored-xss-via-aspectratio"},{"cve":"CVE-2026-13468","cvss":7.5,"slug":"cve-2026-13468-themeisle-visualizer-authorization-bypass-in-rest-api","title":"ThemeIsle Visualizer authorization bypass in REST API","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:18.663+00:00","url":"https://junglewise.ai/threats/cve-2026-13468-themeisle-visualizer-authorization-bypass-in-rest-api"},{"cve":"CVE-2026-12432","cvss":5.3,"slug":"cve-2026-12432-themeisle-wp-full-stripe-free-missing-authorization-in-payment","title":"Themeisle WP Full Stripe Free missing authorization in payment status update","severity":"medium","exploited":false,"published_at":"2026-06-27T08:16:44.563+00:00","url":"https://junglewise.ai/threats/cve-2026-12432-themeisle-wp-full-stripe-free-missing-authorization-in-payment"},{"cve":"CVE-2026-57618","cvss":6.5,"slug":"cve-2026-57618-themeisle-neve-pro-contributor-cross-site-scripting","title":"Themeisle Neve PRO Contributor Cross Site Scripting","severity":"medium","exploited":false,"published_at":"2026-06-26T15:16:49.843+00:00","url":"https://junglewise.ai/threats/cve-2026-57618-themeisle-neve-pro-contributor-cross-site-scripting"},{"cve":"CVE-2026-56050","cvss":6.5,"slug":"cve-2026-56050-themeisle-ppom-for-woocommerce-improper-access-control","title":"Themeisle PPOM for WooCommerce improper access control","severity":"medium","exploited":false,"published_at":"2026-06-25T14:16:50.88+00:00","url":"https://junglewise.ai/threats/cve-2026-56050-themeisle-ppom-for-woocommerce-improper-access-control"},{"cve":"CVE-2026-11358","cvss":4.4,"epss":0.002,"slug":"cve-2026-11358-themeisle-orbit-fox-stored-xss-in-admin-settings","title":"ThemeIsle Orbit Fox Stored XSS in admin settings","severity":"medium","exploited":false,"published_at":"2026-06-18T06:16:56.833+00:00","url":"https://junglewise.ai/threats/cve-2026-11358-themeisle-orbit-fox-stored-xss-in-admin-settings"},{"cve":"CVE-2017-20251","cvss":9.8,"slug":"cve-2017-20251-wordpress-insert-php-plugin-code-injection-via-rest-api","title":"WordPress Insert PHP plugin code injection via REST API","severity":"critical","exploited":false,"published_at":"2026-06-09T13:16:35.14+00:00","url":"https://junglewise.ai/threats/cve-2017-20251-wordpress-insert-php-plugin-code-injection-via-rest-api"},{"cve":"CVE-2026-8976","cvss":4.3,"slug":"cve-2026-8976-themeisle-feedzy-rss-aggregator-authorization-bypass","title":"ThemeIsle Feedzy RSS Aggregator authorization bypass","severity":"medium","exploited":false,"published_at":"2026-06-06T00:16:42.143+00:00","url":"https://junglewise.ai/threats/cve-2026-8976-themeisle-feedzy-rss-aggregator-authorization-bypass"},{"cve":"CVE-2025-53209","cvss":9.8,"slug":"cve-2025-53209-themeisle-masteriyo-lms-pro-privilege-escalation","title":"Themeisle Masteriyo LMS PRO privilege escalation","severity":"critical","exploited":false,"published_at":"2026-06-02T10:16:19.847+00:00","url":"https://junglewise.ai/threats/cve-2025-53209-themeisle-masteriyo-lms-pro-privilege-escalation"},{"cve":"CVE-2026-8689","cvss":4.3,"slug":"cve-2026-8689-themeisle-visualizer-missing-authorization-in-chart-management","title":"ThemeIsle Visualizer missing authorization in chart management functions","severity":"medium","exploited":false,"published_at":"2026-05-28T09:16:48.973+00:00","url":"https://junglewise.ai/threats/cve-2026-8689-themeisle-visualizer-missing-authorization-in-chart-management"},{"cve":"CVE-2026-42749","cvss":7.1,"slug":"cve-2026-42749-themeisle-disable-comments-for-any-post-types-auth-bypass","title":"Themeisle Disable Comments for Any Post Types auth bypass","severity":"high","exploited":false,"published_at":"2026-05-27T11:16:21.413+00:00","url":"https://junglewise.ai/threats/cve-2026-42749-themeisle-disable-comments-for-any-post-types-auth-bypass"},{"cve":"CVE-2026-24573","cvss":6.5,"slug":"cve-2026-24573-themeisle-visualizer-stored-xss-in-wordpress-plugin","title":"Themeisle Visualizer Stored XSS in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-05-20T13:16:16.253+00:00","url":"https://junglewise.ai/threats/cve-2026-24573-themeisle-visualizer-stored-xss-in-wordpress-plugin"}],"vendor":{"hub":true,"name":"Themeisle","slug":"themeisle","homepage":"https://themeisle.com/","description":"A developer of popular WordPress themes and plugins.","url":"https://junglewise.ai/threats/vendors/themeisle"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2017-20251","cvss":9.8,"slug":"cve-2017-20251-wordpress-insert-php-plugin-code-injection-via-rest-api","title":"WordPress Insert PHP plugin code injection via REST API","severity":"critical","exploited":false,"published_at":"2026-06-09T13:16:35.14+00:00","url":"https://junglewise.ai/threats/cve-2017-20251-wordpress-insert-php-plugin-code-injection-via-rest-api"},{"cve":"CVE-2025-53209","cvss":9.8,"slug":"cve-2025-53209-themeisle-masteriyo-lms-pro-privilege-escalation","title":"Themeisle Masteriyo LMS PRO privilege escalation","severity":"critical","exploited":false,"published_at":"2026-06-02T10:16:19.847+00:00","url":"https://junglewise.ai/threats/cve-2025-53209-themeisle-masteriyo-lms-pro-privilege-escalation"},{"cve":"CVE-2026-78285","cvss":8.5,"epss":0.0036,"slug":"cve-2026-78285-like-button-rating-sql-injection","title":"Like Button Rating SQL injection","severity":"high","exploited":false,"published_at":"2026-08-27T10:16:38.01+00:00","url":"https://junglewise.ai/threats/cve-2026-78285-like-button-rating-sql-injection"},{"cve":"CVE-2026-65526","cvss":8.5,"slug":"cve-2026-65526-themeisle-visualizer-sql-injection-in-wordpress-plugin","title":"Themeisle Visualizer SQL injection in WordPress plugin","severity":"high","exploited":false,"published_at":"2026-07-23T12:18:45.393+00:00","url":"https://junglewise.ai/threats/cve-2026-65526-themeisle-visualizer-sql-injection-in-wordpress-plugin"},{"cve":"CVE-2026-13468","cvss":7.5,"slug":"cve-2026-13468-themeisle-visualizer-authorization-bypass-in-rest-api","title":"ThemeIsle Visualizer authorization bypass in REST API","severity":"high","exploited":false,"published_at":"2026-07-01T05:16:18.663+00:00","url":"https://junglewise.ai/threats/cve-2026-13468-themeisle-visualizer-authorization-bypass-in-rest-api"},{"cve":"CVE-2026-42749","cvss":7.1,"slug":"cve-2026-42749-themeisle-disable-comments-for-any-post-types-auth-bypass","title":"Themeisle Disable Comments for Any Post Types auth bypass","severity":"high","exploited":false,"published_at":"2026-05-27T11:16:21.413+00:00","url":"https://junglewise.ai/threats/cve-2026-42749-themeisle-disable-comments-for-any-post-types-auth-bypass"},{"cve":"CVE-2026-86784","cvss":6.8,"epss":0.0043,"slug":"cve-2026-86784-visualizer-wordpress-plugin-stored-xss-in-json-data-source","title":"Visualizer WordPress plugin stored XSS in JSON data source","severity":"medium","exploited":false,"published_at":"2026-09-16T06:16:34.95+00:00","url":"https://junglewise.ai/threats/cve-2026-86784-visualizer-wordpress-plugin-stored-xss-in-json-data-source"},{"cve":"CVE-2026-57618","cvss":6.5,"slug":"cve-2026-57618-themeisle-neve-pro-contributor-cross-site-scripting","title":"Themeisle Neve PRO Contributor Cross Site Scripting","severity":"medium","exploited":false,"published_at":"2026-06-26T15:16:49.843+00:00","url":"https://junglewise.ai/threats/cve-2026-57618-themeisle-neve-pro-contributor-cross-site-scripting"},{"cve":"CVE-2026-56050","cvss":6.5,"slug":"cve-2026-56050-themeisle-ppom-for-woocommerce-improper-access-control","title":"Themeisle PPOM for WooCommerce improper access control","severity":"medium","exploited":false,"published_at":"2026-06-25T14:16:50.88+00:00","url":"https://junglewise.ai/threats/cve-2026-56050-themeisle-ppom-for-woocommerce-improper-access-control"},{"cve":"CVE-2026-24573","cvss":6.5,"slug":"cve-2026-24573-themeisle-visualizer-stored-xss-in-wordpress-plugin","title":"Themeisle Visualizer Stored XSS in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-05-20T13:16:16.253+00:00","url":"https://junglewise.ai/threats/cve-2026-24573-themeisle-visualizer-stored-xss-in-wordpress-plugin"}],"generated_at":"2026-09-26T10:22:00.132594+00:00","technologies":[{"name":"Themeisle Visualizer: Tables and Charts Manager for WordPress","slug":"visualizer","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/visualizer"},{"name":"Themeisle Orbit Fox","slug":"orbit-fox","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/orbit-fox"},{"name":"Themeisle RSS Aggregator by Feedzy","slug":"rss-aggregator-by-feedzy","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/rss-aggregator-by-feedzy"}]}