Vulnerabilities (CVE)

Filtered by vendor Hasthemes Subscribe
Total 96 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-0502 1 Hasthemes 1 Wp News 2026-06-17 N/A 6.5 MEDIUM
The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
CVE-2023-0501 1 Hasthemes 1 Wp Insurance 2026-06-17 N/A 6.5 MEDIUM
The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
CVE-2023-0500 1 Hasthemes 1 Wp Film Studio 2026-06-17 N/A 6.5 MEDIUM
The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
CVE-2023-0499 1 Hasthemes 1 Quickswish 2026-06-17 N/A 4.3 MEDIUM
The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
CVE-2023-0498 1 Hasthemes 1 Wp Education 2026-06-17 N/A 4.3 MEDIUM
The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
CVE-2023-0497 1 Hasthemes 1 Ht Portfolio 2026-06-17 N/A 4.3 MEDIUM
The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
CVE-2023-0496 1 Hasthemes 1 Ht Event 2026-06-17 N/A 4.3 MEDIUM
The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
CVE-2023-0495 1 Hasthemes 1 Ht Slider For Elementor 2026-06-17 N/A 4.3 MEDIUM
The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
CVE-2023-0484 1 Hasthemes 1 Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks 2026-06-17 N/A 4.3 MEDIUM
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
CVE-2023-0232 1 Hasthemes 1 Shoplentor 2026-06-17 N/A 9.8 CRITICAL
The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.
CVE-2023-0231 1 Hasthemes 1 Shoplentor 2026-06-17 N/A 5.4 MEDIUM
The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2022-4650 1 Hasthemes 1 Hashbar 2026-06-17 N/A 5.4 MEDIUM
The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
CVE-2022-47172 1 Hasthemes 1 Woolentor - Woocommerce Elementor Addons \+ Builder 2026-06-17 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.6.2 versions.
CVE-2022-46798 1 Hasthemes 1 Woolentor - Woocommerce Elementor Addons \+ Builder 2026-06-17 N/A 5.4 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.
CVE-2021-24262 1 Hasthemes 1 Woolentor - Woocommerce Elementor Addons \+ Builder 2026-06-17 3.5 LOW 5.4 MEDIUM
The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
CVE-2021-24261 1 Hasthemes 1 Ht Mega 2026-06-17 3.5 LOW 5.4 MEDIUM
The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.