Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

g5theme — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting g5theme. AI-powered Chinese analysis, POCs, and references for each vulnerability.

g5theme operates primarily as a developer of WordPress themes and plugins, catering to content creators and small businesses seeking pre-designed digital templates. Despite its market presence, the company has faced significant scrutiny due to a high volume of security flaws, with thirty-three CVEs currently documented. Historically, these vulnerabilities predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and improper sanitization of user-supplied data within plugin functionalities. These defects have allowed attackers to compromise site integrity, inject malicious scripts, or gain unauthorized administrative access. While specific large-scale breaches directly attributed to g5theme are not widely publicized, the sheer number of disclosed issues highlights systemic weaknesses in their development lifecycle. This pattern necessitates rigorous third-party auditing and immediate patching for users relying on their software to maintain robust cybersecurity postures.

Found 10 results / 34 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-32465 WordPress Essential Real Estate plugin <= 5.3.3 - PHP Object Injection vulnerability — Essential Real Estate CWE-502 8.8 High 2026-08-18
CVE-2025-68071 WordPress Essential Real Estate plugin <= 5.3.2 - Insecure Direct Object References (IDOR) vulnerability — Essential Real Estate CWE-639 6.5 Medium 2025-12-16
CVE-2025-66127 WordPress Essential Real Estate plugin <= 5.3.2 - Broken Access Control vulnerability — Essential Real Estate CWE-862 5.3 Medium 2025-12-16
CVE-2025-48126 WordPress Essential Real Estate plugin <= 5.2.9 - Local File Inclusion vulnerability — Essential Real Estate CWE-98 8.1 High 2025-06-09
CVE-2025-30849 WordPress Essential Real Estate plugin <= 5.2.0 - Local File Inclusion Vulnerability — Essential Real Estate CWE-98 8.1 High 2025-04-01
CVE-2025-24698 WordPress Essential Real Estate plugin <= 5.1.8 - Cross Site Request Forgery (CSRF) vulnerability — Essential Real Estate CWE-352 4.3 Medium 2025-01-24
CVE-2024-12329 Essential Real Estate <= 5.1.6 - Missing Authorization to Authenticated (Contributor+) Information Exposure — Essential Real Estate CWE-200 4.3 Medium 2024-12-12
CVE-2024-4273 Essential Real Estate <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Essential Real Estate CWE-79 6.4 Medium 2024-06-04
CVE-2024-4274 Essential Real Estate <= 4.4.2 - Insecure Direct Object Reference to Arbitrary Attachment Deletion — Essential Real Estate CWE-639 4.3 Medium 2024-06-04
CVE-2023-6827 Essential Real Estate <= 4.3.5 - Authenticated (Subscriber+) Arbitrary File Upload — Essential Real Estate CWE-434 7.5 High 2023-12-15

This page lists every published CVE security advisory associated with g5theme. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.