SecAlerts
t

themeisle

Security Risk Profile

39
/100
low

Security Risk Score

Comprehensive risk assessment based on 83 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 30, 2019 to present

83
Total CVEs
22
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
39/100
low
🆕 3Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
6
High
16
Medium
58
Low
3

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
19

Age Distribution

Common Weaknesses (CWE)

1
XSS
37
2
CSRF
9
3
SQL Injection
8
4
SSRF
5
5
Infoleak
3

Most Affected Products

1. Themeisle Orbit Fox Wordpress15
2. Themeisle Multiple Page Generator Wordpress10
3. Themeisle Otter Blocks Wordpress9
4. Themeisle Rss Aggregator By Feedzy Wordpress9
5. Themeisle Orbit Fox8

Recent Vulnerabilities

See more →
CVE-2026-104953
CVSS 6.8medium

MPG < 4.2.3 - Editor+ SQLi via Project Import

Oct 7, 2026🔧 No Patch
CVE-2026-97305
CVSS 6.9EPSS 0%medium

WordPress AI Chatbot for WordPress – Hyve Lite plugin <= 2.0.2 - Insecure Direct Object References (IDOR) vulnerability

Oct 5, 2026🔧 No Patch
CVE-2026-102002
CVSS 3.1low

Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget

Oct 2, 2026🔧 No Patch
CVE-2026-74992
CVSS 6.8medium

Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload

Aug 20, 2026🔧 No Patch
CVE-2026-16583
CVSS 6.1medium

Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload

Aug 5, 2026🔧 No Patch
CVE-2026-65563
CVSS 5.9medium

WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerability

Jul 27, 2026🔧 No Patch
CVE-2026-61970
CVSS 4.9medium

WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerability

Jul 13, 2026🔧 No Patch
CVE-2026-11358
CVSS 4.4medium

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' Parameter

Jun 18, 2026🔧 No Patch
CVE-2025-53209
CVSS 9.8critical

WordPress Masteriyo LMS PRO plugin <= 2.20.0 - Privilege Escalation Vulnerability

Jun 2, 2026🔧 No Patch
CVE-2026-42749
CVSS 7.1high

WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerability

May 27, 2026🔧 No Patch

Monitor themeisle in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.