Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AncoraThemes — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting AncoraThemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AncoraThemes operates as a digital marketplace specializing in WordPress themes and plugins, catering primarily to web developers and small business owners seeking pre-built website solutions. The company’s extensive portfolio has historically been associated with a significant volume of security flaws, currently totaling 128 recorded Common Vulnerabilities and Exposures (CVEs). These vulnerabilities predominantly stem from insufficient input validation and sanitization, leading to frequent instances of Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection. Additionally, privilege escalation bugs have allowed unauthorized users to gain administrative access, compromising site integrity. While AncoraThemes has implemented security patches for many identified issues, the sheer number of disclosed CVEs highlights systemic challenges in code review processes. Users are advised to exercise caution, ensuring all installed components are updated to the latest secure versions to mitigate potential exploitation risks associated with these legacy and ongoing vulnerabilities.

CVE ID Title CVSS Severity Published
CVE-2025-49363 WordPress Kings & Queens theme <= 1.1.16 - Local File Inclusion vulnerability — Kings & Queens CWE-98 8.1 High 2025-12-18
CVE-2025-49366 WordPress Hanani theme <= 1.2.11 - Local File Inclusion vulnerability — Hanani CWE-98 8.1 High 2025-12-18
CVE-2025-49362 WordPress Gracioza theme <= 1.0.15 - Local File Inclusion vulnerability — Gracioza CWE-98 8.1 High 2025-12-18
CVE-2025-49365 WordPress Jack Well theme <= 1.0.14 - Local File Inclusion vulnerability — Jack Well CWE-98 8.1 High 2025-12-18
CVE-2025-49359 WordPress ShieldGroup theme <= 2.13 - Local File Inclusion vulnerability — ShieldGroup CWE-98 8.1 High 2025-12-18
CVE-2025-49360 WordPress Militarology theme <= 1.0.15 - Local File Inclusion vulnerability — Militarology CWE-98 8.1 High 2025-12-18
CVE-2025-49361 WordPress Mamita theme <= 1.0.9 - Local File Inclusion vulnerability — Mamita CWE-98 8.1 High 2025-12-18
CVE-2025-60225 WordPress BugsPatrol theme <= 1.5.0 - PHP Object Injection vulnerability — BugsPatrol CWE-502 9.8 Critical 2025-10-22
CVE-2025-52815 WordPress CityGov theme <= 1.9 - Local File Inclusion Vulnerability — CityGov CWE-98 8.1 High 2025-06-27
CVE-2025-49072 WordPress Mr. Murphy < 1.2.12.1 - PHP Object Injection Vulnerability — Mr. Murphy CWE-502 9.8 Critical 2025-06-06
CVE-2025-31423 WordPress Umberto theme <= 1.2.8 - PHP Object Injection Vulnerability — Umberto CWE-502 9.8 Critical 2025-05-23
CVE-2025-31631 WordPress Fish House theme <= 1.2.7 - PHP Object Injection Vulnerability — Fish House CWE-502 9.8 Critical 2025-05-23
CVE-2025-32292 WordPress Jarvis – Night Club, Concert, Festival WordPress theme <= 1.8.11 - PHP Object Injection Vulnerability — Jarvis – Night Club, Concert, Festival WordPress CWE-502 9.8 Critical 2025-05-23
CVE-2025-48289 WordPress Kids Planet theme <= 2.2.14 - PHP Object Injection Vulnerability — Kids Planet CWE-502 9.8 Critical 2025-05-23

This page lists every published CVE security advisory associated with AncoraThemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.