Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Edge-Themes — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting Edge-Themes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Edge-Themes develops WordPress themes and templates for website customization, with 13 CVEs recorded to date. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and insecure direct object references. Security researchers have identified consistent patterns in their codebase, particularly in theme options and file handling mechanisms. While no major public security incidents have been widely reported, the accumulation of CVEs suggests ongoing security challenges in their development practices. Their themes' widespread adoption increases potential impact, making regular security updates and careful implementation crucial for users.

CVE ID Title CVSS Severity Published
CVE-2026-104747 WordPress Haaken theme <= 1.5 - PHP Object Injection vulnerability — Haaken CWE-502 8.1 High 2026-10-06
CVE-2026-66653 WordPress Barista theme <= 2.5.1 - Local File Inclusion vulnerability — Barista CWE-98 8.1 High 2026-08-13
CVE-2026-57800 WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability — Overworld CWE-98 7.5 High 2026-07-13
CVE-2026-57788 WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability — Aalto CWE-98 7.5 High 2026-07-13
CVE-2026-40738 WordPress Eldon theme <= 1.4.1 - PHP Object Injection vulnerability — Eldon CWE-502 8.1 High 2026-06-17
CVE-2026-40735 WordPress Reina theme <= 2.1 - PHP Object Injection vulnerability — Reina CWE-502 8.1 High 2026-06-17
CVE-2026-40761 WordPress Valeska theme <= 1.2.2 - PHP Object Injection vulnerability — Valeska CWE-502 8.1 High 2026-06-16
CVE-2026-40760 WordPress Behold theme <= 1.5 - PHP Object Injection vulnerability — Behold CWE-502 8.1 High 2026-06-16
CVE-2026-40736 WordPress Laurits theme <= 1.5.1 - PHP Object Injection vulnerability — Laurits CWE-502 8.1 High 2026-06-16
CVE-2026-39539 WordPress Alloggio - Hotel Booking theme <= 2.1.2 - PHP Object Injection vulnerability — Alloggio - Hotel Booking CWE-502 8.1 High 2026-06-16
CVE-2026-32512 WordPress Pelicula theme < 1.10 - PHP Object Injection vulnerability — Pelicula CWE-502 9.8 Critical 2026-03-25
CVE-2026-32510 WordPress Kamperen theme < 1.3 - Arbitrary Object Instantiation vulnerability — Kamperen CWE-502 5.4 Medium 2026-03-25
CVE-2026-32509 WordPress Gracey theme < 1.4 - Arbitrary Object Instantiation vulnerability — Gracey CWE-502 5.4 Medium 2026-03-25
CVE-2026-32506 WordPress Archicon theme < 1.7 - Arbitrary Object Instantiation vulnerability — Archicon CWE-502 5.4 Medium 2026-03-25
CVE-2025-69410 WordPress Belletrist theme <= 1.2 - Local File Inclusion vulnerability — Belletrist CWE-98 8.1 High 2026-02-20
CVE-2025-69057 WordPress Eldon theme <= 1.0 - Local File Inclusion vulnerability — Eldon CWE-98 8.1 High 2026-01-22
CVE-2025-69050 WordPress Overworld theme <= 1.3 - Local File Inclusion vulnerability — Overworld CWE-98 8.1 High 2026-01-22
CVE-2025-68987 WordPress Cinerama theme <= 2.9 - Local File Inclusion vulnerability — Cinerama CWE-98 7.5 High 2025-12-30
CVE-2025-64287 WordPress Alloggio - Hotel Booking Theme theme <= 1.8 - Local File Inclusion vulnerability — Alloggio - Hotel Booking CWE-98 8.1 High 2025-11-06
CVE-2025-62868 WordPress Edge CPT plugin <= 1.4 - Local File Inclusion vulnerability — Edge CPT CWE-98 8.1 High 2025-10-24
CVE-2025-49889 WordPress Edge CPT plugin <= 1.4 - Local File Inclusion vulnerability — Edge CPT CWE-98 8.1 High 2025-08-20
CVE-2025-3278 UrbanGo Membership <= 1.0.4 - Unauthenticated Privilege Escalation — UrbanGo Membership CWE-269 9.8 Critical 2025-04-19
CVE-2025-1638 Alloggio Membership <= 1.1 - Authentication Bypass via Social Login Account Takeover — Alloggio Membership CWE-288 9.8 Critical 2025-03-01

This page lists every published CVE security advisory associated with Edge-Themes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.