Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ThemeREX — Vulnerabilities & Security Advisories 186

Browse all 186 CVE security advisories affecting ThemeREX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThemeREX operates as a prominent developer of premium WordPress themes and plugins, primarily targeting enterprise and corporate web solutions. Security audits have identified a significant volume of vulnerabilities within its ecosystem, with over 125 Common Vulnerabilities and Exposures (CVEs) currently on record. These flaws predominantly involve cross-site scripting (XSS), SQL injection, and remote code execution (RCE), often stemming from inadequate input validation and improper sanitization of user-supplied data. Additionally, several instances of broken access control and privilege escalation have been documented, allowing unauthorized users to manipulate administrative functions. The high frequency of these issues suggests systemic weaknesses in the development lifecycle, particularly regarding secure coding practices and third-party library management. While the company provides support channels, the sheer number of disclosed vulnerabilities highlights persistent challenges in maintaining robust security hygiene across its extensive product portfolio, posing substantial risks to organizations relying on its software infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-28068 WordPress Rhythmo theme <= 1.3.4 - Local File Inclusion vulnerability — Rhythmo CWE-98 8.1 High 2026-03-05
CVE-2026-28069 WordPress Le Truffe theme <= 1.1.7 - Local File Inclusion vulnerability — Le Truffe CWE-98 8.1 High 2026-03-05
CVE-2026-28065 WordPress Eject theme <= 2.17 - Local File Inclusion vulnerability — Eject CWE-98 8.1 High 2026-03-05
CVE-2026-28066 WordPress Legrand theme <= 2.17 - Local File Inclusion vulnerability — Legrand CWE-98 8.1 High 2026-03-05
CVE-2026-28067 WordPress Bassein theme <= 1.0.15 - Local File Inclusion vulnerability — Bassein CWE-98 8.1 High 2026-03-05
CVE-2026-28062 WordPress Happy Baby theme <= 1.2.12 - Local File Inclusion vulnerability — Happy Baby CWE-98 8.1 High 2026-03-05
CVE-2026-28060 WordPress S.King theme <= 1.5.3 - Local File Inclusion vulnerability — S.King CWE-98 8.1 High 2026-03-05
CVE-2026-28061 WordPress Tiger Claw theme <= 1.1.14 - Local File Inclusion vulnerability — Tiger Claw CWE-98 8.1 High 2026-03-05
CVE-2026-28064 WordPress Edge Decor theme <= 2.2 - Local File Inclusion vulnerability — Edge Decor CWE-98 8.1 High 2026-03-05
CVE-2026-28063 WordPress Asia Garden theme <= 1.3.1 - Local File Inclusion vulnerability — Asia Garden CWE-98 8.1 High 2026-03-05
CVE-2026-28059 WordPress Dermatology Clinic theme <= 1.4.3 - Local File Inclusion vulnerability — Dermatology Clinic CWE-98 8.1 High 2026-03-05
CVE-2026-28057 WordPress Mandala theme <= 2.8 - Local File Inclusion vulnerability — Mandala CWE-98 8.1 High 2026-03-05
CVE-2026-28058 WordPress Dixon theme <= 1.4.2.1 - Local File Inclusion vulnerability — Dixon CWE-98 8.1 High 2026-03-05
CVE-2026-28056 WordPress MCKinney's Politics theme <= 1.2.8 - Local File Inclusion vulnerability — MCKinney's Politics CWE-98 8.1 High 2026-03-05
CVE-2026-28055 WordPress M.Williamson theme <= 1.2.11 - Local File Inclusion vulnerability — M.Williamson CWE-98 8.1 High 2026-03-05
CVE-2026-28052 WordPress Peter Mason theme <= 1.4.5 - Local File Inclusion vulnerability — Peter Mason CWE-98 8.1 High 2026-03-05
CVE-2026-28053 WordPress Miller theme <= 1.3.3 - Local File Inclusion vulnerability — Miller CWE-98 8.1 High 2026-03-05
CVE-2026-28054 WordPress Legal Stone theme <= 1.2.11 - Local File Inclusion vulnerability — Legal Stone CWE-98 8.1 High 2026-03-05
CVE-2026-28051 WordPress Yacht Rental theme <= 2.6 - Local File Inclusion vulnerability — Yacht Rental CWE-98 8.1 High 2026-03-05
CVE-2026-28050 WordPress Beacon theme <= 2.24 - Local File Inclusion vulnerability — Beacon CWE-98 8.1 High 2026-03-05
CVE-2026-28049 WordPress Police Department theme <= 2.17 - Local File Inclusion vulnerability — Police Department CWE-98 8.1 High 2026-03-05
CVE-2026-28045 WordPress N7 | Golf Club Sports & Events theme <= 2.16.0 - Local File Inclusion vulnerability — N7 | Golf Club Sports & Events CWE-98 8.1 High 2026-03-05
CVE-2026-28046 WordPress Law Office theme <= 3.3.0 - Local File Inclusion vulnerability — Law Office CWE-98 8.1 High 2026-03-05
CVE-2026-28043 WordPress Healer - Doctor, Clinic & Medical WordPress Theme theme <= 1.0.0 - Local File Inclusion vulnerability — Healer - Doctor, Clinic & Medical WordPress Theme CWE-98 9.8 Critical 2026-03-05
CVE-2026-28034 WordPress Progress theme <= 1.2 - Local File Inclusion vulnerability — Progress CWE-98 8.1 High 2026-03-05
CVE-2026-28033 WordPress Edifice theme <= 1.8 - Local File Inclusion vulnerability — Edifice CWE-98 8.1 High 2026-03-05
CVE-2026-28035 WordPress Printy theme <= 1.8 - Local File Inclusion vulnerability — Printy CWE-98 8.1 High 2026-03-05
CVE-2026-28031 WordPress Invetex theme <= 2.18 - Local File Inclusion vulnerability — Invetex CWE-98 8.1 High 2026-03-05
CVE-2026-28030 WordPress Bonbon theme <= 1.6 - Local File Inclusion vulnerability — Bonbon CWE-98 8.1 High 2026-03-05
CVE-2026-28032 WordPress Tuning theme <= 1.3 - Local File Inclusion vulnerability — Tuning CWE-98 8.1 High 2026-03-05

This page lists every published CVE security advisory associated with ThemeREX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.