Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ThemeMove — Vulnerabilities & Security Advisories 30

Browse all 30 CVE security advisories affecting ThemeMove. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThemeMove operates as a provider of WordPress themes and plugins, primarily targeting users seeking customizable website designs. Its software portfolio has been associated with twenty-five recorded Common Vulnerabilities and Exposures (CVEs), indicating a significant historical security footprint. Analysis of these vulnerabilities reveals a prevalence of critical flaws, including remote code execution, cross-site scripting, and privilege escalation issues. These defects often stem from insufficient input validation and inadequate sanitization of user-supplied data within the application’s core functions. While specific major incidents involving widespread exploitation are not extensively documented in public threat intelligence feeds, the high volume of CVEs suggests systemic weaknesses in the development lifecycle. Security researchers advise administrators to prioritize regular updates and rigorous patch management to mitigate risks associated with these known defects, ensuring that the underlying infrastructure remains resilient against potential exploitation attempts.

CVE ID Title CVSS Severity Published
CVE-2026-57790 WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability — Billey CWE-98 7.5 High 2026-07-13
CVE-2026-57791 WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability — Brook CWE-98 7.5 High 2026-07-13
CVE-2026-57797 WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability — EduMall CWE-862 4.3 Medium 2026-07-13
CVE-2025-69094 WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability — Unicamp CWE-89 8.5 High 2026-07-02
CVE-2026-39590 WordPress Atomlab theme <= 2.4.5 - Local File Inclusion vulnerability — Atomlab CWE-98 8.1 High 2026-06-17
CVE-2026-25027 WordPress Unicamp theme <= 2.7.1 - Local File Inclusion vulnerability — Unicamp CWE-98 7.5 High 2026-02-03
CVE-2025-22708 WordPress Mitech theme <= 2.3.4 - Local File Inclusion vulnerability — Mitech CWE-98 8.1 High 2026-01-08
CVE-2025-22707 WordPress Moody theme <= 2.7.3 - Local File Inclusion vulnerability — Moody CWE-98 8.1 High 2026-01-08
CVE-2025-14430 WordPress Brook - Agency Business Creative theme <= 2.9.0 - Local File Inclusion vulnerability — Brook CWE-98 8.1 High 2026-01-08
CVE-2025-14429 WordPress AeroLand theme <= 1.6.6 - Local File Inclusion vulnerability — AeroLand CWE-98 8.1 High 2026-01-08
CVE-2025-60069 WordPress MinimogWP theme <= 3.9.6 - Local File Inclusion vulnerability — MinimogWP CWE-98 8.1 High 2025-12-18
CVE-2025-68061 WordPress EduMall theme <= 4.4.7 - Local File Inclusion vulnerability — EduMall CWE-98 7.5 High 2025-12-16
CVE-2025-68062 WordPress MinimogWP theme <= 3.9.6 - Local File Inclusion vulnerability — MinimogWP CWE-98 7.5 High 2025-12-16
CVE-2025-59564 WordPress EduMall Theme < 4.4.5 - Local File Inclusion Vulnerability — EduMall CWE-98 8.1 High 2025-10-22
CVE-2025-59557 WordPress Learts Addons Plugin < 1.7.5 - SQL Injection Vulnerability — Learts Addons CWE-89 9.3 Critical 2025-10-22
CVE-2025-59555 WordPress Medizin Theme < 1.9.7 - Local File Inclusion Vulnerability — Medizin CWE-98 8.1 High 2025-10-22
CVE-2025-59558 WordPress Billey Theme < 2.1.6 - Local File Inclusion Vulnerability — Billey CWE-98 8.1 High 2025-10-22
CVE-2025-58967 WordPress Businext theme < 2.4.4 - Local File Inclusion vulnerability — Businext CWE-98 8.1 High 2025-10-22
CVE-2025-58958 WordPress SmilePure Theme < 1.8.5 - Local File Inclusion Vulnerability — SmilePure CWE-98 8.1 High 2025-10-22
CVE-2025-53303 WordPress ThemeMove Core Plugin <= 1.4.2 - PHP Object Injection Vulnerability — ThemeMove Core CWE-502 8.8 High 2025-09-09
CVE-2025-58206 WordPress MaxCoach Theme <= 3.2.5 - Local File Inclusion Vulnerability — MaxCoach CWE-98 8.1 High 2025-09-05
CVE-2025-58210 WordPress Makeaholic Theme <= 1.8.5 - Broken Access Control Vulnerability — Makeaholic CWE-862 5.3 Medium 2025-09-03
CVE-2025-54700 WordPress Makeaholic Theme <= 1.8.4 - Local File Inclusion Vulnerability — Makeaholic CWE-98 8.1 High 2025-08-14
CVE-2025-54701 WordPress Unicamp Theme <= 2.6.3 - Local File Inclusion Vulnerability — Unicamp CWE-98 8.1 High 2025-08-14
CVE-2025-8198 MinimogWP – The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation — MinimogWP – The High Converting eCommerce WordPress Theme CWE-472 7.5 High 2025-07-26
CVE-2025-39474 WordPress Amely theme <= 3.1.4 - SQL Injection vulnerability — Amely CWE-89 9.3 Critical 2025-06-27
CVE-2025-32309 WordPress Healsoul theme <= 2.2.3 - Local File Inclusion Vulnerability — Healsoul CWE-98 8.1 High 2025-05-23
CVE-2025-32310 WordPress QuickCal plugin <= 1.0.15 - CSRF to Privilege Escalation vulnerability — QuickCal - Appointment Booking Calendar for WordPress CWE-352 8.8 High 2025-05-16
CVE-2025-2101 Edumall <= 4.2.4 - Unauthenticated Local File Inclusion — EduMall - Professional LMS Education Center WordPress Theme CWE-98 8.1 High 2025-04-26
CVE-2024-13790 MinimogWP – The High Converting eCommerce WordPress Theme <= 3.7.0 - Unauthenticated Local PHP File Inclusion — MinimogWP – The High Converting eCommerce WordPress Theme CWE-98 9.8 Critical 2025-03-19

This page lists every published CVE security advisory associated with ThemeMove. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.