plugin

Templatespare Vulnerabilities

3 known security issues reported for the Templatespare WordPress plugin. Most recent disclosed Jul 23, 2026.

1 high 2 medium

Running Templatespare on your site? Check whether your installed version is affected.

Scan your site free

TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder <= 4.2.2 - Missing Authorization

medium

The TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.2.2. This makes it possible for authenticated attackers...

CVSS:
4.3
Affected:
up to 4.2.2
Fix:
No patched version reported
Disclosed:
Jul 23, 2026

CVE-2026-65530 on NVD →

TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder <= 4.2.0 - Authenticated (Admin+) Arbitrary File Upload

high

The TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.2.0. This makes it possible for authenticated attackers, wit...

CVSS:
7.2
Affected:
up to 4.2.0
Fixed in:
4.2.1
Disclosed:
Jun 25, 2026

CVE-2026-57658 on NVD →

Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks! – TemplateSpare <= 2.4.2 - Missing Authorization to Authenticated (Subscriber+) Theme Update

medium

The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks! – TemplateSpare plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'templatespare_activate_required_theme' a...

CVSS:
4.3
Affected:
up to 2.4.2
Fixed in:
2.4.3
Disclosed:
Aug 2, 2024

CVE-2024-6872 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database