Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Mikado-Themes — Vulnerabilities & Security Advisories 84

Browse all 84 CVE security advisories affecting Mikado-Themes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Mikado-Themes operates as a provider of WordPress themes and plugins, primarily targeting e-commerce and general website design. Security audits have identified seventy confirmed Common Vulnerabilities and Exposures (CVEs) associated with its software ecosystem. Historically, these vulnerabilities predominantly stem from insufficient input validation and improper access controls, resulting in critical classes such as Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection. Privilege escalation flaws have also been documented, allowing unauthorized users to gain administrative access. While specific high-profile incidents involving widespread data breaches are not widely publicized, the sheer volume of CVEs indicates systemic issues in the development lifecycle. The lack of robust sanitization in theme functions has consistently exposed user data and server integrity to exploitation. This pattern suggests that security testing was not a primary focus during the software’s creation, leaving numerous installations vulnerable to automated attacks and manual exploitation by threat actors seeking to compromise WordPress-based infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-22414 WordPress Marra theme <= 1.2 - Local File Inclusion vulnerability — Marra CWE-98 8.1 High 2026-03-05
CVE-2026-22405 WordPress Overton theme <= 1.3 - Local File Inclusion vulnerability — Overton CWE-98 8.1 High 2026-03-05
CVE-2026-22410 WordPress Dolcino theme <= 1.6 - Local File Inclusion vulnerability — Dolcino CWE-98 8.1 High 2026-03-05
CVE-2026-22408 WordPress Justicia theme <= 1.2 - Local File Inclusion vulnerability — Justicia CWE-98 8.1 High 2026-03-05
CVE-2026-22413 WordPress Malgré theme <= 1.0.3 - Local File Inclusion vulnerability — Malgré CWE-98 8.1 High 2026-03-05
CVE-2026-22412 WordPress Eona theme <= 1.3 - Local File Inclusion vulnerability — Eona CWE-98 8.1 High 2026-03-05
CVE-2026-22403 WordPress Innovio theme <= 1.9 - Local File Inclusion vulnerability — Innovio CWE-98 8.1 High 2026-03-05
CVE-2026-22399 WordPress Holmes theme <= 1.7 - Local File Inclusion vulnerability — Holmes CWE-98 8.1 High 2026-03-05
CVE-2026-22394 WordPress Evently theme <= 1.7 - Local File Inclusion vulnerability — Evently CWE-98 8.1 High 2026-03-05
CVE-2026-22392 WordPress Cortex theme <= 1.9 - Local File Inclusion vulnerability — Cortex CWE-98 8.1 High 2026-03-05
CVE-2026-22397 WordPress Fleur theme <= 2.2.1 - Local File Inclusion vulnerability — Fleur CWE-98 8.1 High 2026-03-05
CVE-2026-22395 WordPress Fiorello theme <= 1.0 - Local File Inclusion vulnerability — Fiorello CWE-98 8.1 High 2026-03-05
CVE-2026-22389 WordPress Cocco theme <= 2.0 - Local File Inclusion vulnerability — Cocco CWE-98 8.1 High 2026-03-05
CVE-2026-22387 WordPress Aviana theme <= 2.1 - Local File Inclusion vulnerability — Aviana CWE-98 8.1 High 2026-03-05
CVE-2026-22383 WordPress PawFriends - Pet Shop and Veterinary WordPress theme theme <= 1.3 - Insecure Direct Object References (IDOR) vulnerability — PawFriends - Pet Shop and Veterinary WordPress Theme CWE-639 7.5 High 2026-02-20
CVE-2026-22381 WordPress PawFriends - Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Local File Inclusion vulnerability — PawFriends - Pet Shop and Veterinary WordPress Theme CWE-98 8.1 High 2026-02-20
CVE-2026-22344 WordPress FiveStar theme <= 1.7 - Local File Inclusion vulnerability — FiveStar CWE-98 8.1 High 2026-02-20
CVE-2025-69408 WordPress HealthFirst theme <= 1.0.1 - Local File Inclusion vulnerability — HealthFirst CWE-98 8.1 High 2026-02-20
CVE-2026-24631 WordPress Rosebud theme <= 1.4 - Insecure Direct Object References (IDOR) vulnerability — Rosebud CWE-639 5.4 Medium 2026-01-23
CVE-2026-22458 WordPress Wanderland theme <= 1.5 - Broken Access Control vulnerability — Wanderland CWE-862 4.3 Medium 2026-01-22
CVE-2026-22430 WordPress Verdure theme <= 1.6 - Insecure Direct Object References (IDOR) vulnerability — Verdure CWE-639 5.4 Medium 2026-01-22
CVE-2026-22406 WordPress Overton theme <= 1.3 - Insecure Direct Object References (IDOR) vulnerability — Overton CWE-639 5.4 Low 2026-01-22
CVE-2026-22409 WordPress Justicia theme <= 1.2 - Insecure Direct Object References (IDOR) vulnerability — Justicia CWE-639 5.4 Low 2026-01-22
CVE-2026-22407 WordPress Roam theme <= 2.1.1 - Insecure Direct Object References (IDOR) vulnerability — Roam CWE-639 5.4 Low 2026-01-22
CVE-2026-22411 WordPress Dolcino theme <= 1.6 - Insecure Direct Object References (IDOR) vulnerability — Dolcino CWE-639 5.4 Low 2026-01-22
CVE-2026-22398 WordPress Fleur theme <= 2.0 - Insecure Direct Object References (IDOR) vulnerability — Fleur CWE-639 5.4 Medium 2026-01-22
CVE-2026-22404 WordPress Innovio theme <= 1.7 - Insecure Direct Object References (IDOR) vulnerability — Innovio CWE-639 5.4 Low 2026-01-22
CVE-2026-22400 WordPress Holmes theme <= 1.7 - Insecure Direct Object References (IDOR) vulnerability — Holmes CWE-639 5.4 Medium 2026-01-22
CVE-2026-22393 WordPress Curly theme <= 3.3 - Insecure Direct Object References (IDOR) vulnerability — Curly CWE-639 5.4 Medium 2026-01-22
CVE-2026-22396 WordPress Fiorello theme <= 1.0 - Insecure Direct Object References (IDOR) vulnerability — Fiorello CWE-639 5.4 Medium 2026-01-22

This page lists every published CVE security advisory associated with Mikado-Themes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.