theme

Woodmart Vulnerabilities

34 known security issues reported for the Woodmart WordPress theme. Most recent disclosed Jun 25, 2026.

5 high 13 medium

Running Woodmart on your site? Check whether your installed version is affected.

Scan your site free

Woodmart <= 8.5.3 - Unauthenticated Stored Cross-Site Scripting

high

The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in...

CVSS:
7.2
Affected:
up to 8.5.3
Fixed in:
8.5.4
Disclosed:
Jun 25, 2026

CVE-2026-56072 on NVD →

Woodmart <= 8.3.8 - Unauthenticated PHP Object Injection

high

The Woodmart theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.3.8 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an a...

CVSS:
8.1
Affected:
up to 8.3.8
Fixed in:
8.3.9
Disclosed:
Mar 23, 2026

CVE-2026-23971 on NVD →

WoodMart <= 8.3.9 - Unauthenticated Sensitive Information Exposure

medium

The Woodmart theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 8.3.9
Fixed in:
8.4.0
Disclosed:
Feb 22, 2026

CVE-2026-32405 on NVD →

WoodMart [woodmart] <= 8.3.7 (unfixed)

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in xtemos WoodMart woodmart allows Code Injection.This issue affects WoodMart: from n/a through <= 8.3.7.

Affected:
up to 8.3.7
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-47600 on NVD →

WoodMart <= 8.3.7 - Unauthenticated Arbitrary Shortcode Execution

medium

The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.3.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to ex...

CVSS:
6.5
Affected:
up to 8.3.7
Fixed in:
8.3.8
Disclosed:
Jan 9, 2026

CVE-2025-47600 on NVD →

WoodMart [woodmart] < 8.3.2

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart allows PHP Local File Inclusion.This issue affects WoodMart: from n/a through < 8.3.2.

Affected:
up to 8.3.2
Fixed in:
8.3.2
Disclosed:
Oct 22, 2025

CVE-2025-49935 on NVD →

WoodMart [woodmart] < 8.3.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart woodmart allows DOM-Based XSS.This issue affects WoodMart: from n/a through < 8.3.2.

Affected:
up to 8.3.2
Fixed in:
8.3.2
Disclosed:
Oct 22, 2025

CVE-2025-49936 on NVD →

WoodMart < 8.3.2 - Authenticated (Contributor+) Local File Inclusion

high

The WoodMart theme for WordPress is vulnerable to Local File Inclusion in versions up to 8.3.2. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to by...

CVSS:
7.5
Affected:
up to 8.3.2
Fixed in:
8.3.2
Disclosed:
Oct 14, 2025

CVE-2025-49935 on NVD →

WoodMart < 8.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WoodMart theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 8.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenev...

CVSS:
6.4
Affected:
up to 8.3.2
Fixed in:
8.3.2
Disclosed:
Oct 10, 2025

CVE-2025-49936 on NVD →

WoodMart - Multipurpose WooCommerce Theme <= 8.2.6 - Improper Input Validation Leading to Unauthenticated Cart Manipulation

medium

The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient validation of the qty parameter in the woodmart_update_cart_item function. This makes it possible for unauthenticated attackers to manipulate cart quantities using fractio...

CVSS:
5.3
Affected:
up to 8.2.6
Fixed in:
8.2.7
Disclosed:
Jul 25, 2025

CVE-2025-8097 on NVD →

WoodMart <= 8.2.5 - Unauthenticated Post Disclosure

medium

The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_query() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected...

CVSS:
5.3
Affected:
up to 8.2.5
Fixed in:
8.2.6
Disclosed:
Jul 10, 2025

CVE-2025-6745 on NVD →

WoodMart <= 8.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attribute in all versions up to, and including, 8.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...

CVSS:
6.4
Affected:
up to 8.2.3
Fixed in:
8.2.4
Disclosed:
Jul 7, 2025

CVE-2025-6743 on NVD →

WoodMart <= 8.2.3 - Authenticated (Contributor+) Local File Inclusion

high

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution o...

CVSS:
8.8
Affected:
up to 8.2.3
Fixed in:
8.2.4
Disclosed:
Jul 7, 2025

CVE-2025-6746 on NVD →

Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution

high

The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_get_products_shortcode() function. Thi...

CVSS:
7.3
Affected:
up to 8.2.3
Fixed in:
8.2.4
Disclosed:
Jul 7, 2025

CVE-2025-6744 on NVD →

WoodMart [woodmart] < 7.2.2

unknown

[en] Missing Authorization vulnerability in Xtemos WoodMart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WoodMart: from n/a through 7.2.1.

Affected:
up to 7.2.2
Fixed in:
7.2.2
Disclosed:
Jan 2, 2025

CVE-2023-32240 on NVD →

WoodMart [woodmart] < 8.0.4

unknown

[en] The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_instagram_ajax_query AJAX action. Thi...

Affected:
up to 8.0.4
Fixed in:
8.0.4
Disclosed:
Dec 12, 2024

CVE-2024-12333 on NVD →

WoodMart <= 8.0.3 - Unauthenticated Arbitrary Shortcode Execution

medium

The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_instagram_ajax_query AJAX action. This mak...

CVSS:
6.5
Affected:
up to 8.0.3
Fixed in:
8.0.4
Disclosed:
Dec 11, 2024

CVE-2024-12333 on NVD →

WoodMart [woodmart] < 7.1.2

unknown

[en] Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart allows Cross-Site Scripting (XSS).This issue affects WoodMart: from n/a through 7.0.4.

Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Apr 24, 2024

CVE-2023-25790 on NVD →

WoodMart [woodmart] < 7.1.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme <= 7.1.1 versions.

Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Nov 9, 2023

CVE-2023-32500 on NVD →

WoodMart [woodmart] < 7.2.5

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xtemos WoodMart plugin <= 7.2.4 versions.

Affected:
up to 7.2.5
Fixed in:
7.2.5
Disclosed:
Sep 25, 2023

CVE-2023-41872 on NVD →

WoodMart <= 7.2.4 - Reflected Cross-Site Scripting

medium

The WoodMart theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to 7.2.4
Fixed in:
7.2.5
Disclosed:
Sep 5, 2023

CVE-2023-41872 on NVD →

WoodMart [woodmart] < 7.2.2

unknown

[en] Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in xtemos WoodMart theme <= 7.2.1 versions.

Affected:
up to 7.2.2
Fixed in:
7.2.2
Disclosed:
Jun 22, 2023

CVE-2023-32239 on NVD →

WoodMart <= 7.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WoodMart theme for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 7.2.1
Fixed in:
7.2.2
Disclosed:
May 11, 2023

CVE-2023-32239 on NVD →

WoodMart <= 7.2.1 - Missing Authorization

medium

The WoodMart theme for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on an unknown function in versions up to, and including, 7.2.1. This makes it possible for authenticated attackers , with subscriber-level access and above, to invoke this function.

CVSS:
4.3
Affected:
up to 7.2.1
Fixed in:
7.2.2
Disclosed:
May 11, 2023

CVE-2023-32240 on NVD →

Woodmart <= 7.1.1 - Cross-Site Request Forgery to License Update

medium

The Woodmart theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.1.1. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to modify the plugin's license via a forged request granted they can tr...

CVSS:
6.5
Affected:
up to 7.1.1
Fixed in:
7.1.2
Disclosed:
Mar 1, 2023

CVE-2023-32500 on NVD →

WoodMart <= 7.1.1 - Missing Authorization to Shortcode Injection

medium

The WoodMart theme for WordPress is vulnerable to unauthorized shortcode injection in versions up to, and including, 7.1.1. This makes it possible for unauthenticated attackers to inject arbitrary shortcodes. This is only present when the "Display results from blog" setting is enabled.

CVSS:
6.5
Affected:
up to 7.1.1
Fixed in:
7.1.2
Disclosed:
Mar 1, 2023

CVE-2023-25790 on NVD →

WoodMart [woodmart] < 7.1.2

unknown

The Woodmart theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.1.1. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to modify the plugin's license via a forged request granted they can tr...

Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Mar 1, 2023

Woodmart <= 7.0.4 - Unauthenticated Arbitrary Content Injection

medium

The Woodmart theme for WordPress is vulnerable to Arbitrary Content Injection in versions up to, and including, 7.0.4. The cause of this vulnerability is undisclosed at this time. However, this vulnerability makes it possible for unauthenticated attackers to inject new content onto the website, possibly through the man...

CVSS:
5.3
Affected:
up to 7.0.4
Fixed in:
7.1.1
Disclosed:
Feb 16, 2023

CVE-2023-25790 on NVD →

WoodMart [woodmart] < 7.1.2

unknown

The theme does not have CSRF checks when updating and deactivating the license, which could allow attackers to make logged in admins perform such actions via CSRF attacks

Affected:
up to 7.1.2
Fixed in:
7.1.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database