Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AncoraThemes — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting AncoraThemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AncoraThemes operates as a digital marketplace specializing in WordPress themes and plugins, catering primarily to web developers and small business owners seeking pre-built website solutions. The company’s extensive portfolio has historically been associated with a significant volume of security flaws, currently totaling 128 recorded Common Vulnerabilities and Exposures (CVEs). These vulnerabilities predominantly stem from insufficient input validation and sanitization, leading to frequent instances of Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection. Additionally, privilege escalation bugs have allowed unauthorized users to gain administrative access, compromising site integrity. While AncoraThemes has implemented security patches for many identified issues, the sheer number of disclosed CVEs highlights systemic challenges in code review processes. Users are advised to exercise caution, ensuring all installed components are updated to the latest secure versions to mitigate potential exploitation risks associated with these legacy and ongoing vulnerabilities.

CVE IDTitleCVSSSeverityPublished
CVE-2026-22451 WordPress Handyman theme <= 1.4.7 - PHP Object Injection vulnerability — HandymanCWE-502 9.8 Critical2026-03-05
CVE-2026-22439 WordPress Green Planet theme <= 1.1.14 - Local File Inclusion vulnerability — Green PlanetCWE-98 8.1 High2026-03-05
CVE-2026-22437 WordPress Playa theme <= 1.3.9 - Local File Inclusion vulnerability — PlayaCWE-98 8.1 High2026-03-05
CVE-2026-22435 WordPress ElectroServ theme <= 1.3.2 - Local File Inclusion vulnerability — ElectroServCWE-98 8.1 High2026-03-05
CVE-2026-22432 WordPress Woopy theme <= 1.2 - Local File Inclusion vulnerability — WoopyCWE-98 8.1 High2026-03-05
CVE-2026-22433 WordPress CloudMe theme <= 1.2.2 - Local File Inclusion vulnerability — CloudMeCWE-98 8.1 High2026-03-05
CVE-2026-22434 WordPress Crown Art theme <= 1.2.11 - Local File Inclusion vulnerability — Crown ArtCWE-98 8.1 High2026-03-05
CVE-2026-22428 WordPress Tooth Fairy theme <= 1.16 - Local File Inclusion vulnerability — Tooth FairyCWE-98 8.1 High2026-03-05
CVE-2026-22431 WordPress Wabi-Sabi theme <= 1.2 - Local File Inclusion vulnerability — Wabi-SabiCWE-98 8.1 High2026-03-05
CVE-2026-22420 WordPress Horizon theme <= 1.1 - Local File Inclusion vulnerability — HorizonCWE-98 8.1 High2026-03-05
CVE-2026-22424 WordPress Shaha theme <= 1.1.2 - Local File Inclusion vulnerability — ShahaCWE-98 8.1 High2026-03-05
CVE-2026-22419 WordPress Honor theme <= 2.3 - Local File Inclusion vulnerability — HonorCWE-98 8.1 High2026-03-05
CVE-2026-22421 WordPress Quantum theme <= 1.0 - Local File Inclusion vulnerability — QuantumCWE-98 8.1 High2026-03-05
CVE-2026-22415 WordPress The Mounty theme <= 1.1 - Local File Inclusion vulnerability — The MountyCWE-98 8.1 High2026-03-05
CVE-2026-22416 WordPress FixTeam theme <= 1.5.0 - Local File Inclusion vulnerability — FixTeamCWE-98 8.1 High2026-03-05
CVE-2026-22418 WordPress Great Lotus theme <= 1.3.1 - Local File Inclusion vulnerability — Great LotusCWE-98 8.1 High2026-03-05
CVE-2026-22380 WordPress UnlimHost theme <= 1.2.3 - Local File Inclusion vulnerability — UnlimHostCWE-98 8.1 High2026-02-20
CVE-2026-22379 WordPress Netmix theme <= 1.0.10 - Local File Inclusion vulnerability — NetmixCWE-98 8.1 High2026-02-20
CVE-2026-22377 WordPress Saveo theme <= 1.1.2 - Local File Inclusion vulnerability — SaveoCWE-98 8.1 High2026-02-20
CVE-2026-22378 WordPress Blabber theme <= 1.7.0 - Local File Inclusion vulnerability — BlabberCWE-98 8.1 High2026-02-20
CVE-2026-22376 WordPress Parkivia theme <= 1.1.9 - Local File Inclusion vulnerability — ParkiviaCWE-98 8.1 High2026-02-20
CVE-2026-22375 WordPress Impacto Patronus theme <= 1.2.3 - Local File Inclusion vulnerability — Impacto PatronusCWE-98 8.1 High2026-02-20
CVE-2026-22373 WordPress Fooddy theme <= 1.3.10 - Local File Inclusion vulnerability — FooddyCWE-98 8.1 High2026-02-20
CVE-2026-22374 WordPress Zio Alberto theme <= 1.2.2 - Local File Inclusion vulnerability — Zio AlbertoCWE-98 8.1 High2026-02-20
CVE-2026-22369 WordPress Ironfit theme <= 1.5 - Local File Inclusion vulnerability — IronfitCWE-98 8.1 High2026-02-20
CVE-2026-22372 WordPress Isida theme <= 1.4.2 - Local File Inclusion vulnerability — IsidaCWE-98 8.1 High2026-02-20
CVE-2026-22371 WordPress Gustavo theme <= 1.2.2 - Local File Inclusion vulnerability — GustavoCWE-98 8.1 High2026-02-20
CVE-2026-22367 WordPress Coworking theme <= 1.6.1 - Local File Inclusion vulnerability — CoworkingCWE-98 8.1 High2026-02-20
CVE-2025-69372 WordPress SevenHills theme <= 1.6.2 - PHP Object Injection vulnerability — SevenHillsCWE-502 9.8 Critical2026-02-20
CVE-2025-69371 WordPress KindlyCare theme <= 1.6.1 - PHP Object Injection vulnerability — KindlyCareCWE-502 9.8 Critical2026-02-20

This page lists every published CVE security advisory associated with AncoraThemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.