Themewinter Security Vulnerabilities (CVEs)

Track 12 security vulnerabilities affecting Themewinter products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

1 Critical
6 High
5 Medium
🔔 Get Alerts for Themewinter
CVE-2025-4796 8.8

The Eventin WordPress plugin has a privilege escalation vulnerability that allows attackers with contributor-level permissions or higher to change any...

Aug 8, 2025
CVE-2025-49321 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Eventin WordPress plugin. When users visit a specially...

Jun 27, 2025
CVE-2025-47539 9.8

This vulnerability allows attackers to escalate privileges in the Themewinter Eventin WordPress plugin, potentially gaining administrative access. It ...

May 23, 2025
CVE-2025-39584 7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the Eventin WordPress plugin. Attackers ...

Apr 16, 2025
CVE-2025-26964 7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 25, 2025
CVE-2024-56213 6.5

This path traversal vulnerability in the Eventin WordPress plugin allows attackers to access files outside the intended directory using '.../...//' se...

Dec 31, 2024
CVE-2023-49756 5.4

This CVE describes a Missing Authorization vulnerability in the Themewinter Eventin WordPress plugin that allows authenticated users to exploit incorr...

Dec 9, 2024
CVE-2023-47805 5.3

This CVE describes a missing authorization vulnerability in the WPCafe WordPress plugin that allows attackers to bypass access controls. Attackers can...

Dec 9, 2024
CVE-2024-7149 8.8

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform Local File Inclusion attacks in the Eventin...

Sep 27, 2024
CVE-2024-37507 6.5

This stored cross-site scripting (XSS) vulnerability in the Eventin WordPress plugin allows attackers to inject malicious scripts into web pages that ...

Jul 21, 2024
CVE-2024-6033 4.3

This vulnerability in the Eventin WordPress plugin allows authenticated attackers with Contributor-level access or higher to import unauthorized data ...

Jul 17, 2024
CVE-2024-5431 8.8

This vulnerability allows authenticated attackers with Contributor-level access or higher to perform Local File Inclusion via the reservation_extra_fi...

Jun 25, 2024

Why Monitor Themewinter Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 12+ known vulnerabilities affecting Themewinter products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Themewinter packages in under 60 seconds. No agents required - completely agentless scanning that works across Themewinter deployments.

Free vulnerability database: Access detailed information about every Themewinter CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Themewinter CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Themewinter CVEs Free