Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

AncoraThemes — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting AncoraThemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AncoraThemes operates as a digital marketplace specializing in WordPress themes and plugins, catering primarily to web developers and small business owners seeking pre-built website solutions. The company’s extensive portfolio has historically been associated with a significant volume of security flaws, currently totaling 128 recorded Common Vulnerabilities and Exposures (CVEs). These vulnerabilities predominantly stem from insufficient input validation and sanitization, leading to frequent instances of Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection. Additionally, privilege escalation bugs have allowed unauthorized users to gain administrative access, compromising site integrity. While AncoraThemes has implemented security patches for many identified issues, the sheer number of disclosed CVEs highlights systemic challenges in code review processes. Users are advised to exercise caution, ensuring all installed components are updated to the latest secure versions to mitigate potential exploitation risks associated with these legacy and ongoing vulnerabilities.

CVE ID Title CVSS Severity Published
CVE-2026-22451 WordPress Handyman theme <= 1.4.7 - PHP Object Injection vulnerability — Handyman CWE-502 9.8 Critical 2026-03-05
CVE-2026-22439 WordPress Green Planet theme <= 1.1.14 - Local File Inclusion vulnerability — Green Planet CWE-98 8.1 High 2026-03-05
CVE-2026-22437 WordPress Playa theme <= 1.3.9 - Local File Inclusion vulnerability — Playa CWE-98 8.1 High 2026-03-05
CVE-2026-22435 WordPress ElectroServ theme <= 1.3.2 - Local File Inclusion vulnerability — ElectroServ CWE-98 8.1 High 2026-03-05
CVE-2026-22432 WordPress Woopy theme <= 1.2 - Local File Inclusion vulnerability — Woopy CWE-98 8.1 High 2026-03-05
CVE-2026-22433 WordPress CloudMe theme <= 1.2.2 - Local File Inclusion vulnerability — CloudMe CWE-98 8.1 High 2026-03-05
CVE-2026-22434 WordPress Crown Art theme <= 1.2.11 - Local File Inclusion vulnerability — Crown Art CWE-98 8.1 High 2026-03-05
CVE-2026-22428 WordPress Tooth Fairy theme <= 1.16 - Local File Inclusion vulnerability — Tooth Fairy CWE-98 8.1 High 2026-03-05
CVE-2026-22431 WordPress Wabi-Sabi theme <= 1.2 - Local File Inclusion vulnerability — Wabi-Sabi CWE-98 8.1 High 2026-03-05
CVE-2026-22420 WordPress Horizon theme <= 1.1 - Local File Inclusion vulnerability — Horizon CWE-98 8.1 High 2026-03-05
CVE-2026-22424 WordPress Shaha theme <= 1.1.2 - Local File Inclusion vulnerability — Shaha CWE-98 8.1 High 2026-03-05
CVE-2026-22419 WordPress Honor theme <= 2.3 - Local File Inclusion vulnerability — Honor CWE-98 8.1 High 2026-03-05
CVE-2026-22421 WordPress Quantum theme <= 1.0 - Local File Inclusion vulnerability — Quantum CWE-98 8.1 High 2026-03-05
CVE-2026-22415 WordPress The Mounty theme <= 1.1 - Local File Inclusion vulnerability — The Mounty CWE-98 8.1 High 2026-03-05
CVE-2026-22416 WordPress FixTeam theme <= 1.5.0 - Local File Inclusion vulnerability — FixTeam CWE-98 8.1 High 2026-03-05
CVE-2026-22418 WordPress Great Lotus theme <= 1.3.1 - Local File Inclusion vulnerability — Great Lotus CWE-98 8.1 High 2026-03-05
CVE-2026-22380 WordPress UnlimHost theme <= 1.2.3 - Local File Inclusion vulnerability — UnlimHost CWE-98 8.1 High 2026-02-20
CVE-2026-22379 WordPress Netmix theme <= 1.0.10 - Local File Inclusion vulnerability — Netmix CWE-98 8.1 High 2026-02-20
CVE-2026-22377 WordPress Saveo theme <= 1.1.2 - Local File Inclusion vulnerability — Saveo CWE-98 8.1 High 2026-02-20
CVE-2026-22378 WordPress Blabber theme <= 1.7.0 - Local File Inclusion vulnerability — Blabber CWE-98 8.1 High 2026-02-20
CVE-2026-22376 WordPress Parkivia theme <= 1.1.9 - Local File Inclusion vulnerability — Parkivia CWE-98 8.1 High 2026-02-20
CVE-2026-22375 WordPress Impacto Patronus theme <= 1.2.3 - Local File Inclusion vulnerability — Impacto Patronus CWE-98 8.1 High 2026-02-20
CVE-2026-22373 WordPress Fooddy theme <= 1.3.10 - Local File Inclusion vulnerability — Fooddy CWE-98 8.1 High 2026-02-20
CVE-2026-22374 WordPress Zio Alberto theme <= 1.2.2 - Local File Inclusion vulnerability — Zio Alberto CWE-98 8.1 High 2026-02-20
CVE-2026-22369 WordPress Ironfit theme <= 1.5 - Local File Inclusion vulnerability — Ironfit CWE-98 8.1 High 2026-02-20
CVE-2026-22372 WordPress Isida theme <= 1.4.2 - Local File Inclusion vulnerability — Isida CWE-98 8.1 High 2026-02-20
CVE-2026-22371 WordPress Gustavo theme <= 1.2.2 - Local File Inclusion vulnerability — Gustavo CWE-98 8.1 High 2026-02-20
CVE-2026-22367 WordPress Coworking theme <= 1.6.1 - Local File Inclusion vulnerability — Coworking CWE-98 8.1 High 2026-02-20
CVE-2025-69372 WordPress SevenHills theme <= 1.6.2 - PHP Object Injection vulnerability — SevenHills CWE-502 9.8 Critical 2026-02-20
CVE-2025-69371 WordPress KindlyCare theme <= 1.6.1 - PHP Object Injection vulnerability — KindlyCare CWE-502 9.8 Critical 2026-02-20

This page lists every published CVE security advisory associated with AncoraThemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.