Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ThemeREX — Vulnerabilities & Security Advisories 189

Browse all 189 CVE security advisories affecting ThemeREX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThemeREX operates as a prominent developer of premium WordPress themes and plugins, primarily targeting enterprise and corporate web solutions. Security audits have identified a significant volume of vulnerabilities within its ecosystem, with over 125 Common Vulnerabilities and Exposures (CVEs) currently on record. These flaws predominantly involve cross-site scripting (XSS), SQL injection, and remote code execution (RCE), often stemming from inadequate input validation and improper sanitization of user-supplied data. Additionally, several instances of broken access control and privilege escalation have been documented, allowing unauthorized users to manipulate administrative functions. The high frequency of these issues suggests systemic weaknesses in the development lifecycle, particularly regarding secure coding practices and third-party library management. While the company provides support channels, the sheer number of disclosed vulnerabilities highlights persistent challenges in maintaining robust security hygiene across its extensive product portfolio, posing substantial risks to organizations relying on its software infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-27991 WordPress Avventure theme <= 1.1.12 - Local File Inclusion vulnerability — Avventure CWE-98 8.1 High 2026-03-05
CVE-2026-27992 WordPress Meals & Wheels theme <= 1.1.12 - Local File Inclusion vulnerability — Meals & Wheels CWE-98 8.1 High 2026-03-05
CVE-2026-27993 WordPress Aldo theme <= 1.0.10 - Local File Inclusion vulnerability — Aldo CWE-98 8.1 High 2026-03-05
CVE-2026-27990 WordPress ConFix theme <= 1.013 - Local File Inclusion vulnerability — ConFix CWE-98 8.1 High 2026-03-05
CVE-2026-27988 WordPress Equadio theme <= 1.1.3 - Local File Inclusion vulnerability — Equadio CWE-98 8.1 High 2026-03-05
CVE-2026-27989 WordPress Quanzo theme <= 1.0.10 - Local File Inclusion vulnerability — Quanzo CWE-98 8.1 High 2026-03-05
CVE-2026-27986 WordPress OsTende theme <= 1.4.3 - Local File Inclusion vulnerability — OsTende CWE-98 8.1 High 2026-03-05
CVE-2026-27985 WordPress Humanum theme <= 1.1.4 - Local File Inclusion vulnerability — Humanum CWE-98 8.1 High 2026-03-05
CVE-2026-27987 WordPress The Qlean theme <= 2.12 - Local File Inclusion vulnerability — The Qlean CWE-98 8.1 High 2026-03-05
CVE-2026-27439 WordPress Dentario theme <= 1.5 - PHP Object Injection vulnerability — Dentario CWE-502 9.8 Critical 2026-03-05
CVE-2026-27437 WordPress Tennis Club theme <= 1.2.3 - PHP Object Injection vulnerability — Tennis Club CWE-502 9.8 Critical 2026-03-05
CVE-2026-27438 WordPress Kingler theme <= 1.7 - PHP Object Injection vulnerability — Kingler CWE-502 9.8 Critical 2026-03-05
CVE-2026-22474 WordPress Equestrian Centre theme <= 1.5 - PHP Object Injection vulnerability — Equestrian Centre CWE-502 9.8 Critical 2026-03-05
CVE-2026-22454 WordPress Solaris theme <= 2.5 - PHP Object Injection vulnerability — Solaris CWE-502 9.8 Critical 2026-03-05
CVE-2026-22452 WordPress Hoverex theme <= 1.5.10 - Local File Inclusion vulnerability — Hoverex CWE-98 8.1 High 2026-03-05
CVE-2026-22453 WordPress Pets Club theme <= 2.3 - PHP Object Injection vulnerability — Pets Club CWE-502 9.8 Critical 2026-03-05
CVE-2026-22443 WordPress Alliance theme <= 3.1.1 - Local File Inclusion vulnerability — Alliance CWE-98 8.1 High 2026-03-05
CVE-2025-54001 WordPress Classter theme <= 2.5 - PHP Object Injection vulnerability — Classter CWE-502 9.8 Critical 2026-03-05
CVE-2025-53335 WordPress Berger theme <= 1.1.1 - Local File Inclusion vulnerability — Berger CWE-98 8.1 High 2026-03-05
CVE-2025-69405 WordPress Lorem Ipsum | Books & Media Store theme <= 1.2.11 - PHP Object Injection vulnerability — Lorem Ipsum | Books & Media Store CWE-502 9.8 Critical 2026-02-20
CVE-2025-69406 WordPress FreightCo theme <= 1.1.7 - Local File Inclusion vulnerability — FreightCo CWE-98 8.1 High 2026-02-20
CVE-2025-69404 WordPress Extreme Store theme <= 1.5.10 - PHP Object Injection vulnerability — Extreme Store CWE-502 9.8 Critical 2026-02-20
CVE-2025-69402 WordPress R&F theme <= 1.5 - Local File Inclusion vulnerability — R&F CWE-98 8.1 High 2026-02-20
CVE-2025-69399 WordPress Cobble theme <= 1.7 - Local File Inclusion vulnerability — Cobble CWE-98 8.1 High 2026-02-20
CVE-2025-69400 WordPress Yokoo theme <= 1.1.11 - Local File Inclusion vulnerability — Yokoo CWE-98 8.1 High 2026-02-20
CVE-2025-69398 WordPress Plank theme <= 1.7 - Local File Inclusion vulnerability — Plank CWE-98 8.1 High 2026-02-20
CVE-2025-69397 WordPress Tint theme <= 1.7 - Local File Inclusion vulnerability — Tint CWE-98 8.1 High 2026-02-20
CVE-2025-69395 WordPress Gable theme <= 1.5 - Local File Inclusion vulnerability — Gable CWE-98 8.1 High 2026-02-20
CVE-2025-69396 WordPress Splendour theme <= 1.23 - Local File Inclusion vulnerability — Splendour CWE-98 8.1 High 2026-02-20
CVE-2025-69079 WordPress Sound | Musical Instruments Online Store theme <= 1.6.9 - Deserialization of untrusted data vulnerability — Sound | Musical Instruments Online Store CWE-502 9.8 Critical 2026-01-22

This page lists every published CVE security advisory associated with ThemeREX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.