Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

AncoraThemes — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting AncoraThemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AncoraThemes operates as a digital marketplace specializing in WordPress themes and plugins, catering primarily to web developers and small business owners seeking pre-built website solutions. The company’s extensive portfolio has historically been associated with a significant volume of security flaws, currently totaling 128 recorded Common Vulnerabilities and Exposures (CVEs). These vulnerabilities predominantly stem from insufficient input validation and sanitization, leading to frequent instances of Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection. Additionally, privilege escalation bugs have allowed unauthorized users to gain administrative access, compromising site integrity. While AncoraThemes has implemented security patches for many identified issues, the sheer number of disclosed CVEs highlights systemic challenges in code review processes. Users are advised to exercise caution, ensuring all installed components are updated to the latest secure versions to mitigate potential exploitation risks associated with these legacy and ongoing vulnerabilities.

CVE ID Title CVSS Severity Published
CVE-2025-60043 WordPress Wanderic theme <= 1.0.10 - Local File Inclusion vulnerability — Wanderic CWE-98 8.1 High 2025-12-18
CVE-2025-58900 WordPress UniTravel theme <= 1.4.2 - Local File Inclusion vulnerability — UniTravel CWE-98 8.1 High 2025-12-18
CVE-2025-58901 WordPress Takeout theme <= 1.3.0 - Local File Inclusion vulnerability — Takeout CWE-98 8.1 High 2025-12-18
CVE-2025-58899 WordPress Frame theme <= 2.4.0 - Local File Inclusion vulnerability — Frame CWE-98 8.1 High 2025-12-18
CVE-2025-58898 WordPress HealthHub theme <= 1.3.0 - Local File Inclusion vulnerability — HealthHub CWE-98 8.1 High 2025-12-18
CVE-2025-58895 WordPress Integro theme <= 1.8.0 - Local File Inclusion vulnerability — Integro CWE-98 8.1 High 2025-12-18
CVE-2025-58896 WordPress Otaku theme <= 1.8.0 - Local File Inclusion vulnerability — Otaku CWE-98 8.1 High 2025-12-18
CVE-2025-58890 WordPress Playful theme <= 1.19.0 - Local File Inclusion vulnerability — Playful CWE-98 8.1 High 2025-12-18
CVE-2025-58892 WordPress Tourimo theme <= 1.2.3 - Local File Inclusion vulnerability — Tourimo CWE-98 8.1 High 2025-12-18
CVE-2025-58891 WordPress Sanger theme <= 1.24.0 - Local File Inclusion vulnerability — Sanger CWE-98 8.1 High 2025-12-18
CVE-2025-58888 WordPress The Flash theme <= 1.15 - Local File Inclusion vulnerability — The Flash CWE-98 8.1 High 2025-12-18
CVE-2025-58885 WordPress Pathfinder theme <= 1.16 - Local File Inclusion vulnerability — Pathfinder CWE-98 8.1 High 2025-12-18
CVE-2025-58879 WordPress Festy theme <= 1.13.0 - Local File Inclusion vulnerability — Festy CWE-98 8.1 High 2025-12-18
CVE-2025-53431 WordPress Emberlyn theme <= 1.3.1 - Local File Inclusion vulnerability — Emberlyn CWE-98 8.1 High 2025-12-18
CVE-2025-53433 WordPress EasyEat theme <= 1.9.0 - Local File Inclusion vulnerability — EasyEat CWE-98 9.8 Critical 2025-12-18
CVE-2025-53430 WordPress Etta theme <= 1.14.0 - Local File Inclusion vulnerability — Etta CWE-98 8.1 High 2025-12-18
CVE-2025-53434 WordPress ChildHope theme <= 1.1.8 - Local File Inclusion vulnerability — ChildHope CWE-98 8.1 High 2025-12-18
CVE-2025-53432 WordPress Echo theme <= 1.15.0 - Local File Inclusion vulnerability — Echo CWE-98 8.1 High 2025-12-18
CVE-2025-53429 WordPress Exit Game theme <= 1.4.3 - Local File Inclusion vulnerability — Exit Game CWE-98 8.1 High 2025-12-18
CVE-2025-52745 WordPress Farm Agrico theme <= 1.3.11 - Local File Inclusion vulnerability — Farm Agrico CWE-98 8.1 High 2025-12-18
CVE-2025-52768 WordPress Faith & Hope theme <= 2.13.0 - Local File Inclusion vulnerability — Faith & Hope CWE-98 8.1 High 2025-12-18
CVE-2025-49942 WordPress Gardis theme <= 1.2.13 - Local File Inclusion vulnerability — Gardis CWE-98 8.1 High 2025-12-18
CVE-2025-49943 WordPress Femme theme <= 1.3.11 - Local File Inclusion vulnerability — Femme CWE-98 8.1 High 2025-12-18
CVE-2025-49941 WordPress GlamChic theme <= 1.0.11 - Local File Inclusion vulnerability — GlamChic CWE-98 8.1 High 2025-12-18
CVE-2025-49371 WordPress Strux theme <= 1.9 - Local File Inclusion vulnerability — Strux CWE-98 8.1 High 2025-12-18
CVE-2025-49369 WordPress Lettuce theme <= 1.1.7 - Local File Inclusion vulnerability — Lettuce CWE-98 8.1 High 2025-12-18
CVE-2025-49370 WordPress Lymcoin theme <= 1.3.12 - Local File Inclusion vulnerability — Lymcoin CWE-98 8.1 High 2025-12-18
CVE-2025-49368 WordPress Palladio theme <= 1.1.10 - Local File Inclusion vulnerability — Palladio CWE-98 8.1 High 2025-12-18
CVE-2025-49367 WordPress Monyxi theme <= 1.1.8 - Local File Inclusion vulnerability — Monyxi CWE-98 8.1 High 2025-12-18
CVE-2025-49364 WordPress Ludos Paradise theme <= 2.1.3 - Local File Inclusion vulnerability — Ludos Paradise CWE-98 8.1 High 2025-12-18

This page lists every published CVE security advisory associated with AncoraThemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.