{"schema_version":1,"title":"VillaTheme vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in VillaTheme: 0 in the last 7 days and 7 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-81786, was published on 10 September 2026.","url":"https://junglewise.ai/threats/vendors/villatheme","json_url":"https://junglewise.ai/threats/vendors/villatheme.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/villatheme","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":11,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":7,"last_365_days":11},"latest":[{"cve":"CVE-2026-81786","cvss":7.5,"epss":0.0039,"slug":"cve-2026-81786-thank-you-page-customizer-for-woocommerce-broken-access-control","title":"Thank You Page Customizer for WooCommerce broken access control","severity":"high","exploited":false,"published_at":"2026-09-10T15:17:44.077+00:00","url":"https://junglewise.ai/threats/cve-2026-81786-thank-you-page-customizer-for-woocommerce-broken-access-control"},{"cve":"CVE-2026-81282","cvss":6.5,"epss":0.0022,"slug":"cve-2026-81282-product-variations-swatches-for-woocommerce-cross-site-scripting","title":"Product Variations Swatches for WooCommerce cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-09-03T17:17:24.033+00:00","url":"https://junglewise.ai/threats/cve-2026-81282-product-variations-swatches-for-woocommerce-cross-site-scripting"},{"cve":"CVE-2026-82227","cvss":8.5,"epss":0.0036,"slug":"cve-2026-82227-wpbulky-sql-injection-in-contributor-functionality","title":"WPBulky SQL Injection in contributor functionality","severity":"high","exploited":false,"published_at":"2026-08-28T16:18:32.163+00:00","url":"https://junglewise.ai/threats/cve-2026-82227-wpbulky-sql-injection-in-contributor-functionality"},{"cve":"CVE-2026-57698","cvss":6.5,"slug":"cve-2026-57698-villatheme-abandoned-cart-recovery-for-woocommerce-authentication","title":"VillaTheme Abandoned Cart Recovery for WooCommerce authentication bypass","severity":"medium","exploited":false,"published_at":"2026-07-13T10:16:37.26+00:00","url":"https://junglewise.ai/threats/cve-2026-57698-villatheme-abandoned-cart-recovery-for-woocommerce-authentication"},{"cve":"CVE-2026-57422","cvss":7.1,"slug":"cve-2026-57422-villatheme-bopo-reflected-xss-in-woocommerce-product-bundle","title":"VillaTheme Bopo Reflected XSS in WooCommerce Product Bundle Builder","severity":"high","exploited":false,"published_at":"2026-07-13T10:16:36.2+00:00","url":"https://junglewise.ai/threats/cve-2026-57422-villatheme-bopo-reflected-xss-in-woocommerce-product-bundle"},{"cve":"CVE-2026-11778","cvss":5.4,"slug":"cve-2026-11778-villatheme-curcy-multi-currency-for-woocommerce-arbitrary","title":"VillaTheme CURCY Multi Currency for WooCommerce arbitrary shortcode execution","severity":"medium","exploited":false,"published_at":"2026-07-03T09:16:36.497+00:00","url":"https://junglewise.ai/threats/cve-2026-11778-villatheme-curcy-multi-currency-for-woocommerce-arbitrary"},{"cve":"CVE-2026-57352","cvss":4.8,"slug":"cve-2026-57352-villatheme-ald-dropshipping-broken-authentication","title":"VillaTheme ALD Dropshipping broken authentication","severity":"medium","exploited":false,"published_at":"2026-07-02T12:17:35.48+00:00","url":"https://junglewise.ai/threats/cve-2026-57352-villatheme-ald-dropshipping-broken-authentication"},{"cve":"CVE-2026-57664","cvss":4.3,"slug":"cve-2026-57664-villatheme-bopo-woocommerce-product-bundle-builder-sensitive-data","title":"VillaTheme Bopo WooCommerce Product Bundle Builder sensitive data exposure","severity":"medium","exploited":false,"published_at":"2026-06-26T15:16:55.573+00:00","url":"https://junglewise.ai/threats/cve-2026-57664-villatheme-bopo-woocommerce-product-bundle-builder-sensitive-data"},{"cve":"CVE-2026-57324","cvss":6.5,"slug":"cve-2026-57324-villatheme-gift4u-broken-access-control-in-wordpress-plugin","title":"VillaTheme GIFT4U broken access control in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-06-26T15:16:49.097+00:00","url":"https://junglewise.ai/threats/cve-2026-57324-villatheme-gift4u-broken-access-control-in-wordpress-plugin"},{"cve":"CVE-2026-54809","cvss":9.3,"epss":0.0024,"slug":"cve-2026-54809-villatheme-gift4u-blind-sql-injection","title":"VillaTheme GIFT4U Blind SQL injection","severity":"critical","exploited":false,"published_at":"2026-06-17T14:17:58.837+00:00","url":"https://junglewise.ai/threats/cve-2026-54809-villatheme-gift4u-blind-sql-injection"},{"cve":"CVE-2026-39593","cvss":6.5,"slug":"cve-2026-39593-villatheme-happy-missing-authorization-in-helpdesk-support-ticket","title":"VillaTheme HAPPY missing authorization in Helpdesk Support Ticket System","severity":"medium","exploited":false,"published_at":"2026-05-21T18:16:17.203+00:00","url":"https://junglewise.ai/threats/cve-2026-39593-villatheme-happy-missing-authorization-in-helpdesk-support-ticket"}],"vendor":{"hub":true,"name":"VillaTheme","slug":"villatheme","homepage":"https://villatheme.com/","description":"A developer of plugins and extensions for the WordPress content management system.","url":"https://junglewise.ai/threats/vendors/villatheme"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-54809","cvss":9.3,"epss":0.0024,"slug":"cve-2026-54809-villatheme-gift4u-blind-sql-injection","title":"VillaTheme GIFT4U Blind SQL injection","severity":"critical","exploited":false,"published_at":"2026-06-17T14:17:58.837+00:00","url":"https://junglewise.ai/threats/cve-2026-54809-villatheme-gift4u-blind-sql-injection"},{"cve":"CVE-2026-82227","cvss":8.5,"epss":0.0036,"slug":"cve-2026-82227-wpbulky-sql-injection-in-contributor-functionality","title":"WPBulky SQL Injection in contributor functionality","severity":"high","exploited":false,"published_at":"2026-08-28T16:18:32.163+00:00","url":"https://junglewise.ai/threats/cve-2026-82227-wpbulky-sql-injection-in-contributor-functionality"},{"cve":"CVE-2026-81786","cvss":7.5,"epss":0.0039,"slug":"cve-2026-81786-thank-you-page-customizer-for-woocommerce-broken-access-control","title":"Thank You Page Customizer for WooCommerce broken access control","severity":"high","exploited":false,"published_at":"2026-09-10T15:17:44.077+00:00","url":"https://junglewise.ai/threats/cve-2026-81786-thank-you-page-customizer-for-woocommerce-broken-access-control"},{"cve":"CVE-2026-57422","cvss":7.1,"slug":"cve-2026-57422-villatheme-bopo-reflected-xss-in-woocommerce-product-bundle","title":"VillaTheme Bopo Reflected XSS in WooCommerce Product Bundle Builder","severity":"high","exploited":false,"published_at":"2026-07-13T10:16:36.2+00:00","url":"https://junglewise.ai/threats/cve-2026-57422-villatheme-bopo-reflected-xss-in-woocommerce-product-bundle"},{"cve":"CVE-2026-81282","cvss":6.5,"epss":0.0022,"slug":"cve-2026-81282-product-variations-swatches-for-woocommerce-cross-site-scripting","title":"Product Variations Swatches for WooCommerce cross-site scripting","severity":"medium","exploited":false,"published_at":"2026-09-03T17:17:24.033+00:00","url":"https://junglewise.ai/threats/cve-2026-81282-product-variations-swatches-for-woocommerce-cross-site-scripting"},{"cve":"CVE-2026-57698","cvss":6.5,"slug":"cve-2026-57698-villatheme-abandoned-cart-recovery-for-woocommerce-authentication","title":"VillaTheme Abandoned Cart Recovery for WooCommerce authentication bypass","severity":"medium","exploited":false,"published_at":"2026-07-13T10:16:37.26+00:00","url":"https://junglewise.ai/threats/cve-2026-57698-villatheme-abandoned-cart-recovery-for-woocommerce-authentication"},{"cve":"CVE-2026-57324","cvss":6.5,"slug":"cve-2026-57324-villatheme-gift4u-broken-access-control-in-wordpress-plugin","title":"VillaTheme GIFT4U broken access control in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-06-26T15:16:49.097+00:00","url":"https://junglewise.ai/threats/cve-2026-57324-villatheme-gift4u-broken-access-control-in-wordpress-plugin"},{"cve":"CVE-2026-39593","cvss":6.5,"slug":"cve-2026-39593-villatheme-happy-missing-authorization-in-helpdesk-support-ticket","title":"VillaTheme HAPPY missing authorization in Helpdesk Support Ticket System","severity":"medium","exploited":false,"published_at":"2026-05-21T18:16:17.203+00:00","url":"https://junglewise.ai/threats/cve-2026-39593-villatheme-happy-missing-authorization-in-helpdesk-support-ticket"},{"cve":"CVE-2026-11778","cvss":5.4,"slug":"cve-2026-11778-villatheme-curcy-multi-currency-for-woocommerce-arbitrary","title":"VillaTheme CURCY Multi Currency for WooCommerce arbitrary shortcode execution","severity":"medium","exploited":false,"published_at":"2026-07-03T09:16:36.497+00:00","url":"https://junglewise.ai/threats/cve-2026-11778-villatheme-curcy-multi-currency-for-woocommerce-arbitrary"},{"cve":"CVE-2026-57352","cvss":4.8,"slug":"cve-2026-57352-villatheme-ald-dropshipping-broken-authentication","title":"VillaTheme ALD Dropshipping broken authentication","severity":"medium","exploited":false,"published_at":"2026-07-02T12:17:35.48+00:00","url":"https://junglewise.ai/threats/cve-2026-57352-villatheme-ald-dropshipping-broken-authentication"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[]}