PatchSiren

VillaTheme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM VillaTheme CVE published 2026-10-05

CVE-2026-97071

CVE-2026-97071 is an Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency that allows Integer Attacks. The issue affects CURCY from n/a through 2.2.17. The CVSS score is 5.3, and the severity is MEDIUM. This vulnerability requires verification of affected versions and assessment of exposure to Integer Attacks. Defenders should prioritize verifying the affected versions and assessing [truncated]

HIGH villatheme CVE published 2026-10-03

CVE-2026-101923

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion. An unauthenticated attacker can delete arbitrary posts, pages, products, or media attachments when an administrator deletes the attacker's review or when WordPress's built-in wp_scheduled_delete cron empties the comment trash after 30 days. This vulnerability exists due to the plugin storing attacker-contro [truncated]

MEDIUM VillaTheme CVE published 2026-07-13

CVE-2026-57698

CVE-2026-57698 is an Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce. The issue affects Abandoned Cart Recovery for WooCommerce from n/a through <= 1.1.12. According to the CVE record, the vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. This vulnerability allows for Authentication Abuse, potentially leading to una [truncated]

HIGH VillaTheme CVE published 2026-07-13

CVE-2026-57422

A Reflected XSS vulnerability exists in the Bopo – WooCommerce Product Bundle Builder plugin due to improper neutralization of input during web page generation. This issue affects versions from n/a through <= 1.2.0. Users of affected versions should be aware of this vulnerability and take necessary precautions. The CVE record was published on 2026-07-13T10:16:36.200Z and has not been modified since then.

CRITICAL VillaTheme CVE published 2026-06-17

CVE-2026-54809

A critical SQL injection vulnerability was discovered in the GIFT4U plugin, affecting versions up to 1.0.10. This vulnerability allows for blind SQL injection, posing a significant risk to affected systems. The vulnerability was publicly disclosed on June 17, 2026, and has been rated with a CVSS score of 9.3, indicating a critical severity level. The vulnerability is caused by improper neutralization of s [truncated]

MEDIUM VillaTheme CVE published 2026-05-21

CVE-2026-39593

CVE-2026-39593 describes a missing-authorization flaw in the VillaTheme HAPPY WordPress plugin, affecting versions through 1.0.10. The issue is mapped to broken access control (CWE-862) and scored CVSS 6.5 (medium), with network attack conditions and no user interaction required. Because the source corpus does not provide a confirmed fixed version or a clear vendor ownership record, the safest stance is t [truncated]