Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ThemeREX — Vulnerabilities & Security Advisories 189

Browse all 189 CVE security advisories affecting ThemeREX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThemeREX operates as a prominent developer of premium WordPress themes and plugins, primarily targeting enterprise and corporate web solutions. Security audits have identified a significant volume of vulnerabilities within its ecosystem, with over 125 Common Vulnerabilities and Exposures (CVEs) currently on record. These flaws predominantly involve cross-site scripting (XSS), SQL injection, and remote code execution (RCE), often stemming from inadequate input validation and improper sanitization of user-supplied data. Additionally, several instances of broken access control and privilege escalation have been documented, allowing unauthorized users to manipulate administrative functions. The high frequency of these issues suggests systemic weaknesses in the development lifecycle, particularly regarding secure coding practices and third-party library management. While the company provides support channels, the sheer number of disclosed vulnerabilities highlights persistent challenges in maintaining robust security hygiene across its extensive product portfolio, posing substantial risks to organizations relying on its software infrastructure.

CVE ID Title CVSS Severity Published
CVE-2025-69081 WordPress Hope theme <= 3.0.0 - Local File Inclusion vulnerability — Hope CWE-98 8.1 High 2026-01-07
CVE-2025-49890 WordPress Organic Beauty Theme <= 1.4.6 - PHP Object Injection Vulnerability — Organic Beauty CWE-502 9.8 Critical 2025-08-20
CVE-2025-6997 ThemeREX Addons <= 2.35.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via trx_addons_get_svg_from_file Function — ThemeREX Addons CWE-79 6.4 Medium 2025-07-19
CVE-2024-13786 Education Center | LMS & Online Courses WordPress Theme <= 3.6.10 - PHP Object Injection — Education Center | LMS & Online Courses WordPress Theme CWE-502 9.8 Critical 2025-07-02
CVE-2024-13770 Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Object Injection — Puzzles | WP Magazine / Review with Store WordPress Theme + RTL CWE-502 8.1 High 2025-02-13
CVE-2025-0837 Puzzles <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Puzzles | WP Magazine / Review with Store WordPress Theme + RTL CWE-79 6.4 Medium 2025-02-13
CVE-2024-13769 Puzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — Puzzles | WP Magazine / Review with Store WordPress Theme + RTL CWE-862 6.4 Medium 2025-02-12
CVE-2024-13448 ThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_data — ThemeREX Addons CWE-434 9.8 Critical 2025-01-28
CVE-2025-0682 ThemeREX Addons <= 2.33.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode — ThemeREX Addons CWE-98 8.8 High 2025-01-25

This page lists every published CVE security advisory associated with ThemeREX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.