Himalayas
Himalayas has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2024.
2 independent researchers contributed these findings, one record each. Himalayas is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2024-39629Himalayas <= 1.3.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Himalayas
Author
ThemeGrill
Himalayas is modern style free one page parallax responsive WordPress theme. Inform your visitors all they need to know right from your home page without requiring to go to the other pages. Himalayas can be used for business, portfolio, corporate, agency, photography, freelancers and almost any kind of sites. Get free support at https://themegrill.com/contact/ and check the demo at https://themegrilldemos.com/himalayas/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C