Himalayas

Himalayas has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2024.

2 independent researchers contributed these findings, one record each. Himalayas is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all Himalayas vulnerabilities before they are exploited.

Most severe open issueCVSS 4.4CVE-2024-39629

Himalayas <= 1.3.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Himalayas screenshot
Latestv1.3.5
4.9(108)
98/100
Last Updated
2025-08-13 (1y ago)
Active Installs
3,000+
Downloads
345,815
Requires WP
0+
Requires PHP
5.6+
Created
2015-10-07 (11y ago)

Himalayas is modern style free one page parallax responsive WordPress theme. Inform your visitors all they need to know right from your home page without requiring to go to the other pages. Himalayas can be used for business, portfolio, corporate, agency, photography, freelancers and almost any kind of sites. Get free support at https://themegrill.com/contact/ and check the demo at https://themegrilldemos.com/himalayas/

Tags
BlogPortfolioE commerceOne columnCustom menuSticky postTwo columnsLeft sidebarRight sidebarTheme optionsFooter widgetsFeatured imagesThreaded commentsTranslation ready

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C