Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ThemeREX — Vulnerabilities & Security Advisories 189

Browse all 189 CVE security advisories affecting ThemeREX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThemeREX operates as a prominent developer of premium WordPress themes and plugins, primarily targeting enterprise and corporate web solutions. Security audits have identified a significant volume of vulnerabilities within its ecosystem, with over 125 Common Vulnerabilities and Exposures (CVEs) currently on record. These flaws predominantly involve cross-site scripting (XSS), SQL injection, and remote code execution (RCE), often stemming from inadequate input validation and improper sanitization of user-supplied data. Additionally, several instances of broken access control and privilege escalation have been documented, allowing unauthorized users to manipulate administrative functions. The high frequency of these issues suggests systemic weaknesses in the development lifecycle, particularly regarding secure coding practices and third-party library management. While the company provides support channels, the sheer number of disclosed vulnerabilities highlights persistent challenges in maintaining robust security hygiene across its extensive product portfolio, posing substantial risks to organizations relying on its software infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-97236 WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulnerability — ThemeREX Addons CWE-79 6.5 Medium 2026-09-30
CVE-2026-97235 WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulnerability — ThemeREX Addons CWE-79 7.1 High 2026-09-30
CVE-2026-62105 WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability — ThemeREX Addons CWE-502 9.8 Critical 2026-09-11
CVE-2026-65573 WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability — Abelle CWE-502 9.8 Critical 2026-08-06
CVE-2026-57747 WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerability — Booked CWE-352 6.5 Medium 2026-07-02
CVE-2026-57746 WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability — Booked CWE-862 7.1 High 2026-07-02
CVE-2025-69175 WordPress Line Agency theme <= 1.3.1 - Local File Inclusion vulnerability — Line Agency CWE-98 8.1 High 2026-06-17
CVE-2025-69174 WordPress Etude theme <= 1.6 - Local File Inclusion vulnerability — Etude CWE-98 8.1 High 2026-06-17
CVE-2025-69170 WordPress Eventicity theme <= 1.5 - Local File Inclusion vulnerability — Eventicity CWE-98 8.1 High 2026-06-17
CVE-2025-69166 WordPress Gunslinger theme <= 1.7 - Local File Inclusion vulnerability — Gunslinger CWE-98 8.1 High 2026-06-17
CVE-2025-69164 WordPress Skyward theme <= 1.10 - Local File Inclusion vulnerability — Skyward CWE-98 8.1 High 2026-06-17
CVE-2025-69158 WordPress Granola theme <= 1.13 - Local File Inclusion vulnerability — Granola CWE-98 8.1 High 2026-06-17
CVE-2025-69157 WordPress Gamic theme <= 1.15 - Local File Inclusion vulnerability — Gamic CWE-98 8.1 High 2026-06-17
CVE-2025-69144 WordPress Preservation theme <= 1.10 - Local File Inclusion vulnerability — Preservation CWE-98 8.1 High 2026-06-17
CVE-2025-69127 WordPress Plumbing theme <= 1.6 - PHP Object Injection vulnerability — Plumbing CWE-502 9.8 Critical 2026-06-17
CVE-2025-69126 WordPress Fortius theme <= 2.3.0 - Local File Inclusion vulnerability — Fortius CWE-98 8.1 High 2026-06-17
CVE-2025-69123 WordPress Snow Club theme <= 1.1 - Local File Inclusion vulnerability — Snow Club CWE-98 8.1 High 2026-06-17
CVE-2025-69115 WordPress LuxMed | Medicine & Healthcare Doctor WordPress Theme theme <= 1.2.2 - Local File Inclusion vulnerability — LuxMed | Medicine & Healthcare Doctor WordPress Theme CWE-98 8.1 High 2026-06-17
CVE-2025-69120 WordPress Dazzle theme <= 1.0.0 - Local File Inclusion vulnerability — Dazzle CWE-98 8.1 High 2026-06-17
CVE-2025-69111 WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability — Reisen CWE-502 9.8 Critical 2026-06-17
CVE-2025-69106 WordPress Imba theme <= 1.5.0 - Local File Inclusion vulnerability — Imba CWE-98 8.1 High 2026-06-17
CVE-2026-22338 WordPress EcoBlue theme <= 1.15 - Local File Inclusion vulnerability — EcoBlue CWE-98 8.1 High 2026-06-17
CVE-2026-22331 WordPress AutoParts theme <= 1.5.8 - Local File Inclusion vulnerability — AutoParts CWE-98 8.1 High 2026-06-17
CVE-2025-69173 WordPress Tipsy theme <= 1.1 - Local File Inclusion vulnerability — Tipsy CWE-98 8.1 High 2026-06-17
CVE-2025-69172 WordPress Resurs theme <= 1.3 - Local File Inclusion vulnerability — Resurs CWE-98 8.1 High 2026-06-17
CVE-2025-69171 WordPress Orpheus theme <= 1.3 - Local File Inclusion vulnerability — Orpheus CWE-98 8.1 High 2026-06-17
CVE-2025-69161 WordPress Snowy theme <= 1.13 - Local File Inclusion vulnerability — Snowy CWE-98 8.1 High 2026-06-17
CVE-2025-69148 WordPress Quirky theme <= 1.23 - Local File Inclusion vulnerability — Quirky CWE-98 8.1 High 2026-06-17
CVE-2025-69145 WordPress Gat theme <= 1.16 - Local File Inclusion vulnerability — Gat CWE-98 8.1 High 2026-06-17
CVE-2025-69110 WordPress AirSupply theme <= 2.0.0 - Local File Inclusion vulnerability — AirSupply CWE-98 8.1 High 2026-06-17

This page lists every published CVE security advisory associated with ThemeREX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.