Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ThemeREX — Vulnerabilities & Security Advisories 189

Browse all 189 CVE security advisories affecting ThemeREX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThemeREX operates as a prominent developer of premium WordPress themes and plugins, primarily targeting enterprise and corporate web solutions. Security audits have identified a significant volume of vulnerabilities within its ecosystem, with over 125 Common Vulnerabilities and Exposures (CVEs) currently on record. These flaws predominantly involve cross-site scripting (XSS), SQL injection, and remote code execution (RCE), often stemming from inadequate input validation and improper sanitization of user-supplied data. Additionally, several instances of broken access control and privilege escalation have been documented, allowing unauthorized users to manipulate administrative functions. The high frequency of these issues suggests systemic weaknesses in the development lifecycle, particularly regarding secure coding practices and third-party library management. While the company provides support channels, the sheer number of disclosed vulnerabilities highlights persistent challenges in maintaining robust security hygiene across its extensive product portfolio, posing substantial risks to organizations relying on its software infrastructure.

CVE ID Title CVSS Severity Published
CVE-2025-69117 WordPress Ingenioso theme <= 1.14.0 - Local File Inclusion vulnerability — Ingenioso CWE-98 8.1 High 2026-06-17
CVE-2025-60205 WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerability — ThemeREX Addons CWE-502 9.8 Critical 2026-06-17
CVE-2025-58954 WordPress HomeRoofer theme <= 2.11.0 - Local File Inclusion vulnerability — HomeRoofer CWE-98 8.1 High 2026-06-17
CVE-2025-58953 WordPress Joly theme <= 1.22.0 - Local File Inclusion vulnerability — Joly CWE-98 8.1 High 2026-06-17
CVE-2025-58952 WordPress Neuronet theme < 1.14.0 - Local File Inclusion vulnerability — Neuronet CWE-98 8.1 High 2026-06-17
CVE-2025-69176 WordPress ITactics theme <= 1.0 - Local File Inclusion vulnerability — ITactics CWE-98 8.1 High 2026-06-16
CVE-2025-69168 WordPress Spike theme <= 1.2 - Local File Inclusion vulnerability — Spike CWE-98 8.1 High 2026-06-16
CVE-2025-69167 WordPress Eros theme <= 1.3 - Local File Inclusion vulnerability — Eros CWE-98 8.1 High 2026-06-16
CVE-2025-69165 WordPress Choreo theme <= 1.6 - Local File Inclusion vulnerability — Choreo CWE-98 8.1 High 2026-06-16
CVE-2025-69162 WordPress Grecko theme <= 5.17 - Local File Inclusion vulnerability — Grecko CWE-98 8.1 High 2026-06-16
CVE-2025-69163 WordPress WineShop theme <= 3.17 - Local File Inclusion vulnerability — WineShop CWE-98 8.1 High 2026-06-16
CVE-2025-69159 WordPress Printo theme <= 1.11 - Local File Inclusion vulnerability — Printo CWE-98 8.1 High 2026-06-16
CVE-2025-69160 WordPress Gita theme <= 1.11 - Local File Inclusion vulnerability — Gita CWE-98 8.1 High 2026-06-16
CVE-2025-69150 WordPress Medeus theme <= 1.14 - Local File Inclusion vulnerability — Medeus CWE-98 8.1 High 2026-06-16
CVE-2025-69149 WordPress Top Dog theme <= 1.0.5 - Local File Inclusion vulnerability — Top Dog CWE-98 8.1 High 2026-06-16
CVE-2025-69147 WordPress Putter theme <= 1.17 - Local File Inclusion vulnerability — Putter CWE-98 8.1 High 2026-06-16
CVE-2025-69146 WordPress Dom theme <= 1.24 - Local File Inclusion vulnerability — Dom CWE-98 8.1 High 2026-06-16
CVE-2025-69143 WordPress Mission theme <= 1.22 - Local File Inclusion vulnerability — Mission CWE-98 8.1 High 2026-06-16
CVE-2025-69142 WordPress Abelle theme <= 1.22 - Local File Inclusion vulnerability — Abelle CWE-98 8.1 High 2026-06-16
CVE-2025-69141 WordPress Kelly Young theme <= 1.1.0 - Local File Inclusion vulnerability — Kelly Young CWE-98 8.1 High 2026-06-16
CVE-2025-69125 WordPress Food Drop theme <= 1.3 - Local File Inclusion vulnerability — Food Drop CWE-98 8.1 High 2026-06-16
CVE-2025-69122 WordPress SeaFood Company theme <= 1.4 - PHP Object Injection vulnerability — SeaFood Company CWE-502 9.8 Critical 2026-06-16
CVE-2025-69124 WordPress Especio theme <= 1.0 - Local File Inclusion vulnerability — Especio CWE-98 8.1 High 2026-06-16
CVE-2025-69121 WordPress Deliciosa theme <= 1.10.0 - Local File Inclusion vulnerability — Deliciosa CWE-98 8.1 High 2026-06-16
CVE-2025-69119 WordPress Corbesier theme <= 1.15.0 - Local File Inclusion vulnerability — Corbesier CWE-98 8.1 High 2026-06-16
CVE-2025-69118 WordPress CopyPress theme <= 1.4.5 - Local File Inclusion vulnerability — CopyPress CWE-98 8.1 High 2026-06-16
CVE-2025-69114 WordPress MaxiNet theme <= 1.2.10 - Local File Inclusion vulnerability — MaxiNet CWE-98 8.1 High 2026-06-16
CVE-2025-69116 WordPress Iona theme <= 1.0.8 - Local File Inclusion vulnerability — Iona CWE-98 8.1 High 2026-06-16
CVE-2025-69113 WordPress Nexio theme <= 1.10.0 - Local File Inclusion vulnerability — Nexio CWE-98 8.1 High 2026-06-16
CVE-2025-69109 WordPress Raider Spirit theme <= 1.1.2 - Local File Inclusion vulnerability — Raider Spirit CWE-98 8.1 High 2026-06-16

This page lists every published CVE security advisory associated with ThemeREX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.