Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Elated-Themes — Vulnerabilities & Security Advisories 53

Browse all 53 CVE security advisories affecting Elated-Themes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Elated-Themes operates as a software vendor specializing in digital themes and plugins, primarily targeting content management systems. Historical security audits reveal a pattern of critical vulnerabilities, with thirty-one Common Vulnerabilities and Exposures (CVEs) currently documented. The most prevalent flaw types include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation, indicating systemic weaknesses in input validation and access control mechanisms. These defects often stem from insufficient sanitization of user-supplied data and improper handling of administrative functions. While specific major incidents involving widespread exploitation are not explicitly detailed in public records, the high volume of disclosed CVEs suggests a consistent history of security lapses. This profile highlights the necessity for rigorous code review and proactive patch management to mitigate the inherent risks associated with the vendor’s software ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-22498 WordPress Laurent theme <= 3.1 - Local File Inclusion vulnerability — Laurent CWE-98 8.1 High 2026-03-25
CVE-2026-22499 WordPress Lella theme <= 1.2 - Local File Inclusion vulnerability — Lella CWE-98 8.1 High 2026-03-25
CVE-2026-22493 WordPress Gaspard theme <= 1.3 - Local File Inclusion vulnerability — Gaspard CWE-98 8.1 High 2026-03-25
CVE-2026-22478 WordPress FindAll theme <= 1.4 - Local File Inclusion vulnerability — FindAll CWE-98 8.1 High 2026-03-05
CVE-2026-22476 WordPress Etchy theme <= 1.0 - Local File Inclusion vulnerability — Etchy CWE-98 8.1 High 2026-03-05
CVE-2026-22456 WordPress Askka theme <= 1.0 - Local File Inclusion vulnerability — Askka CWE-98 8.1 High 2026-03-05
CVE-2026-22441 WordPress Zentrum theme <= 1.0 - Local File Inclusion vulnerability — Zentrum CWE-98 8.1 High 2026-03-05
CVE-2026-22436 WordPress Helvig theme <= 1.0 - Local File Inclusion vulnerability — Helvig CWE-98 8.1 High 2026-03-05
CVE-2026-22425 WordPress Sweet Jane theme <= 1.2 - Local File Inclusion vulnerability — Sweet Jane CWE-98 8.1 High 2026-03-05
CVE-2026-24609 WordPress Laurent theme <= 3.1 - Local File Inclusion vulnerability — Laurent CWE-98 7.5 High 2026-01-23
CVE-2026-24608 WordPress Laurent Core plugin <= 2.4.1 - Local File Inclusion vulnerability — Laurent Core CWE-98 7.5 High 2026-01-23
CVE-2026-22426 WordPress Sweet Jane theme <= 1.2 - Insecure Direct Object References (IDOR) vulnerability — Sweet Jane CWE-639 5.4 Medium 2026-01-22
CVE-2025-69049 WordPress Töbel theme <= 1.6 - Local File Inclusion vulnerability — Töbel CWE-98 8.1 High 2026-01-22
CVE-2025-69005 WordPress Search & Go theme <= 2.8 - Local File Inclusion vulnerability — Search & Go CWE-98 8.1 High 2026-01-22
CVE-2025-67941 WordPress The Aisle theme < 2.9.1 - Local File Inclusion vulnerability — The Aisle CWE-98 8.1 High 2026-01-22
CVE-2025-67920 WordPress Neo Ocular theme < 1.2 - Local File Inclusion vulnerability — Neo Ocular CWE-98 8.1 High 2026-01-08
CVE-2025-69083 WordPress Frappé theme <= 1.8 - Local File Inclusion vulnerability — Frappé CWE-98 8.1 High 2026-01-06
CVE-2025-66534 WordPress The Aisle theme <= 2.9 - Broken Access Control vulnerability — The Aisle CWE-862 4.3 Medium 2025-12-09
CVE-2025-62067 WordPress Savory theme <= 2.5 - Local File Inclusion vulnerability — Savory CWE-98 8.1 High 2025-11-06
CVE-2025-62064 WordPress Search & Go theme <= 2.7 - Broken Authentication vulnerability — Search & Go CWE-288 9.8 Critical 2025-11-06
CVE-2025-62055 WordPress Academist theme < 1.3 - Local File Inclusion vulnerability — Academist CWE-98 8.1 High 2025-11-06
CVE-2025-11522 Search & Go - Directory WordPress Theme <= 2.7 - Authentication Bypass to Privilege Escalation via Account Takeover — Search & Go - Directory WordPress Theme CWE-288 9.8 Critical 2025-10-09
CVE-2025-1671 Academist Membership <= 1.1.6 - Authentication Bypass via Account Takeover — Academist Membership CWE-288 9.8 Critical 2025-03-01

This page lists every published CVE security advisory associated with Elated-Themes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.