Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

AncoraThemes — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting AncoraThemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AncoraThemes operates as a digital marketplace specializing in WordPress themes and plugins, catering primarily to web developers and small business owners seeking pre-built website solutions. The company’s extensive portfolio has historically been associated with a significant volume of security flaws, currently totaling 128 recorded Common Vulnerabilities and Exposures (CVEs). These vulnerabilities predominantly stem from insufficient input validation and sanitization, leading to frequent instances of Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection. Additionally, privilege escalation bugs have allowed unauthorized users to gain administrative access, compromising site integrity. While AncoraThemes has implemented security patches for many identified issues, the sheer number of disclosed CVEs highlights systemic challenges in code review processes. Users are advised to exercise caution, ensuring all installed components are updated to the latest secure versions to mitigate potential exploitation risks associated with these legacy and ongoing vulnerabilities.

CVE ID Title CVSS Severity Published
CVE-2026-65577 WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability — Advice CWE-502 9.8 Critical 2026-08-06
CVE-2026-65578 WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability — Agora CWE-502 9.8 Critical 2026-08-06
CVE-2026-65576 WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability — Adrena CWE-502 9.8 Critical 2026-08-06
CVE-2026-65575 WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability — Accalia CWE-502 9.8 Critical 2026-08-06
CVE-2026-65574 WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability — Abogado CWE-502 9.8 Critical 2026-08-06
CVE-2025-58902 WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability — Lighthouse CWE-98 8.1 High 2026-07-02
CVE-2026-22515 WordPress VegaDays theme <= 1.2.0 - Local File Inclusion vulnerability — VegaDays CWE-98 8.1 High 2026-03-25
CVE-2026-22514 WordPress Unica theme <= 1.4.1 - Local File Inclusion vulnerability — Unica CWE-98 8.1 High 2026-03-25
CVE-2026-22516 WordPress Wizor's theme <= 2.12 - Local File Inclusion vulnerability — Wizor's CWE-98 8.1 High 2026-03-25
CVE-2026-22510 WordPress Melody theme <= 1.6.3 - PHP Object Injection vulnerability — Melody CWE-502 8.1 High 2026-03-25
CVE-2026-22513 WordPress Triompher theme <= 1.1.0 - Local File Inclusion vulnerability — Triompher CWE-98 8.1 High 2026-03-25
CVE-2026-22507 WordPress Beelove theme <= 1.2.6 - PHP Object Injection vulnerability — Beelove CWE-502 9.8 Critical 2026-03-25
CVE-2026-22508 WordPress Dentalux theme <= 3.3 - Local File Inclusion vulnerability — Dentalux CWE-98 8.1 High 2026-03-25
CVE-2026-22505 WordPress Morning Records theme <= 1.2 - PHP Object Injection vulnerability — Morning Records CWE-502 8.1 High 2026-03-25
CVE-2026-22502 WordPress Mr. Cobbler theme <= 1.1.9 - Local File Inclusion vulnerability — Mr. Cobbler CWE-98 8.1 High 2026-03-25
CVE-2026-22496 WordPress Hypnotherapy theme <= 1.2.10 - Local File Inclusion vulnerability — Hypnotherapy CWE-98 8.1 High 2026-03-25
CVE-2026-22495 WordPress Greenville theme <= 1.3.2 - Local File Inclusion vulnerability — Greenville CWE-98 8.1 High 2026-03-25
CVE-2026-28123 WordPress Veil theme <= 1.9 - Local File Inclusion vulnerability — Veil CWE-98 8.1 High 2026-03-05
CVE-2026-28125 WordPress Midi theme <= 1.14 - Local File Inclusion vulnerability — Midi CWE-98 8.1 High 2026-03-05
CVE-2026-28124 WordPress Notarius theme <= 1.9 - Local File Inclusion vulnerability — Notarius CWE-98 8.1 High 2026-03-05
CVE-2026-28121 WordPress Anderson theme <= 1.4.2 - Local File Inclusion vulnerability — Anderson CWE-98 8.1 High 2026-03-05
CVE-2026-28041 WordPress Grit theme <= 1.0.1 - Local File Inclusion vulnerability — Grit CWE-98 8.1 High 2026-03-05
CVE-2026-27340 WordPress Apollo | Night Club, DJ Event WordPress Theme theme <= 1.3.1 - Local File Inclusion vulnerability — Apollo | Night Club, DJ Event WordPress Theme CWE-98 8.1 High 2026-03-05
CVE-2026-27339 WordPress Buzz Stone | Magazine & Viral Blog WordPress Theme theme <= 1.0.2 - Local File Inclusion vulnerability — Buzz Stone | Magazine & Viral Blog WordPress Theme CWE-98 8.1 High 2026-03-05
CVE-2026-27337 WordPress Chronicle - Lifestyle Magazine & Blog WordPress Theme theme <= 1.0 - Local File Inclusion vulnerability — Chronicle - Lifestyle Magazine & Blog WordPress Theme CWE-98 8.1 High 2026-03-05
CVE-2026-27336 WordPress Consultor | Consulting, Accounting & Legal Counsel WordPress Theme theme <= 1.2.4 - Local File Inclusion vulnerability — Consultor | Consulting, Accounting & Legal Counsel WordPress Theme CWE-98 8.1 High 2026-03-05
CVE-2026-27335 WordPress Ekoterra - NonProfit, Green Energy & Ecology Theme theme <= 1.0.0 - Local File Inclusion vulnerability — Ekoterra - NonProfit, Green Energy & Ecology Theme CWE-98 8.1 High 2026-03-05
CVE-2026-27097 WordPress CasaMia | Property Rental Real Estate WordPress Theme theme <= 1.1.2 - Local File Inclusion vulnerability — CasaMia | Property Rental Real Estate WordPress Theme CWE-98 8.1 High 2026-03-05
CVE-2026-22497 WordPress Jardi theme <= 1.7.2 - PHP Object Injection vulnerability — Jardi CWE-502 9.8 Critical 2026-03-05
CVE-2026-22477 WordPress Felizia theme <= 1.3.4 - Local File Inclusion vulnerability — Felizia CWE-98 8.1 High 2026-03-05

This page lists every published CVE security advisory associated with AncoraThemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.