Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Elated-Themes — Vulnerabilities & Security Advisories 53

Browse all 53 CVE security advisories affecting Elated-Themes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Elated-Themes operates as a software vendor specializing in digital themes and plugins, primarily targeting content management systems. Historical security audits reveal a pattern of critical vulnerabilities, with thirty-one Common Vulnerabilities and Exposures (CVEs) currently documented. The most prevalent flaw types include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation, indicating systemic weaknesses in input validation and access control mechanisms. These defects often stem from insufficient sanitization of user-supplied data and improper handling of administrative functions. While specific major incidents involving widespread exploitation are not explicitly detailed in public records, the high volume of disclosed CVEs suggests a consistent history of security lapses. This profile highlights the necessity for rigorous code review and proactive patch management to mitigate the inherent risks associated with the vendor’s software ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-78478 Måne <= 1.7 - Unauthenticated Local File Inclusion — Mane CWE-98 8.1 High 2026-08-25
CVE-2026-66670 WordPress Måne theme <= 1.7 - Local File Inclusion vulnerability — Måne CWE-98 8.1 High 2026-08-24
CVE-2026-66671 WordPress Verdure Core plugin <= 1.2 - Local File Inclusion vulnerability — Verdure Core CWE-98 8.1 High 2026-08-24
CVE-2026-65481 WordPress Vino theme <= 1.9 - Local File Inclusion vulnerability — Vino CWE-98 7.5 High 2026-07-23
CVE-2026-57793 WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability — Flow CWE-98 7.5 High 2026-07-13
CVE-2026-42382 WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability — Audrey CWE-98 8.1 High 2026-07-02
CVE-2026-39576 WordPress SingleMalt theme <= 1.5 - PHP Object Injection vulnerability — SingleMalt CWE-502 8.1 High 2026-06-17
CVE-2026-39556 WordPress Konsept theme <= 1.9 - PHP Object Injection vulnerability — Konsept CWE-502 8.1 High 2026-06-17
CVE-2026-39523 WordPress Solene Core plugin <= 2.3.2 - Local File Inclusion vulnerability — Solene Core CWE-98 8.1 High 2026-06-17
CVE-2026-39558 WordPress Malmö theme <= 2.2 - Local File Inclusion vulnerability — Malmö CWE-98 8.1 High 2026-06-17
CVE-2026-40758 WordPress Léonie theme <= 1.2.1 - PHP Object Injection vulnerability — Léonie CWE-502 8.1 High 2026-06-16
CVE-2026-40754 WordPress Roisin theme <= 1.4 - PHP Object Injection vulnerability — Roisin CWE-502 8.1 High 2026-06-16
CVE-2026-39578 WordPress Valiance theme <= 1.2 - PHP Object Injection vulnerability — Valiance CWE-502 8.1 Medium 2026-06-16
CVE-2026-39568 WordPress Mr. SEO theme <= 2.0 - Local File Inclusion vulnerability — Mr. SEO CWE-98 8.1 High 2026-06-16
CVE-2026-39577 WordPress Playroom theme <= 1.4.1 - PHP Object Injection vulnerability — Playroom CWE-502 8.1 Medium 2026-06-16
CVE-2026-39557 WordPress NeoBeat theme <= 1.7 - PHP Object Injection vulnerability — NeoBeat CWE-502 8.1 High 2026-06-16
CVE-2026-39554 WordPress Fidalgo theme <= 1.2.2 - PHP Object Injection vulnerability — Fidalgo CWE-502 8.1 High 2026-06-16
CVE-2026-39549 WordPress Aperitif theme <= 1.5 - Local File Inclusion vulnerability — Aperitif CWE-98 8.1 High 2026-06-16
CVE-2026-39522 WordPress Solene theme <= 3.4 - Local File Inclusion vulnerability — Solene CWE-98 8.1 High 2026-06-16
CVE-2026-39555 WordPress Askka theme <= 1.3.1 - PHP Object Injection vulnerability — Askka CWE-502 8.1 High 2026-06-02
CVE-2026-39551 WordPress Töbel theme <= 1.8.1 - PHP Object Injection vulnerability — Töbel CWE-502 8.1 High 2026-06-02
CVE-2026-39550 WordPress Aperitif theme <= 1.6 - PHP Object Injection vulnerability — Aperitif CWE-502 8.1 High 2026-06-02
CVE-2026-32507 WordPress Leroux theme < 1.4 - Arbitrary Object Instantiation vulnerability — Leroux CWE-502 5.4 Medium 2026-03-25
CVE-2026-27048 WordPress The Aisle Core plugin <= 2.0.5 - Local File Inclusion vulnerability — The Aisle Core CWE-98 8.1 High 2026-03-25
CVE-2026-24972 WordPress Elated Listing plugin <= 1.4 - Broken Access Control vulnerability — Elated Listing CWE-862 6.5 Medium 2026-03-25
CVE-2026-24971 WordPress Search & Go theme <= 2.8 - Privilege Escalation vulnerability — Search & Go CWE-266 9.8 Critical 2026-03-25
CVE-2026-22511 WordPress NeoBeat theme <= 1.2 - Local File Inclusion vulnerability — NeoBeat CWE-98 8.1 High 2026-03-25
CVE-2026-22512 WordPress Roisin theme <= 1.2.1 - Local File Inclusion vulnerability — Roisin CWE-98 8.1 High 2026-03-25
CVE-2026-22506 WordPress Amoli theme <= 1.0 - Local File Inclusion vulnerability — Amoli CWE-98 8.1 High 2026-03-25
CVE-2026-22509 WordPress Gioia theme <= 1.4 - Local File Inclusion vulnerability — Gioia CWE-98 8.1 High 2026-03-25

This page lists every published CVE security advisory associated with Elated-Themes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.