Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

axiomthemes — Vulnerabilities & Security Advisories 98

Browse all 98 CVE security advisories affecting axiomthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Axiomthemes operates as a digital marketplace primarily distributing WordPress themes and plugins for web developers and business owners. Security audits reveal a concerning pattern of vulnerabilities, with approximately 85 Common Vulnerabilities and Exposures (CVEs) currently documented. The most prevalent issues involve Cross-Site Scripting (XSS) and Remote Code Execution (RCE), often stemming from insufficient input validation and sanitization within plugin code. Additionally, several incidents highlight broken access control mechanisms, allowing unauthorized privilege escalation for lower-level user roles. These flaws frequently enable attackers to inject malicious scripts or execute arbitrary commands on compromised servers. While the company provides standard support channels, the high volume of disclosed CVEs suggests inconsistent security review processes prior to product release. Users are advised to rigorously audit any installed components, as the historical data indicates a significant risk profile associated with their software ecosystem.

CVE ID Title CVSS Severity Published
CVE-2025-58934 WordPress The Gig theme <= 1.18.0 - Local File Inclusion vulnerability — The Gig CWE-98 8.1 High 2025-12-18
CVE-2025-58936 WordPress Catamaran theme <= 1.15 - Local File Inclusion vulnerability — Catamaran CWE-98 8.1 High 2025-12-18
CVE-2025-58933 WordPress Anubis theme <= 1.25 - Local File Inclusion vulnerability — Anubis CWE-98 8.1 High 2025-12-18
CVE-2025-58929 WordPress Pantry theme <= 1.4 - Local File Inclusion vulnerability — Pantry CWE-98 8.1 High 2025-12-18
CVE-2025-58928 WordPress Heart theme <= 1.8 - Local File Inclusion vulnerability — Heart CWE-98 8.1 High 2025-12-18
CVE-2025-58932 WordPress Prisma theme <= 1.10 - Local File Inclusion vulnerability — Prisma CWE-98 8.1 High 2025-12-18
CVE-2025-58930 WordPress FitFlex theme <= 1.6 - Local File Inclusion vulnerability — FitFlex CWE-98 8.1 High 2025-12-18
CVE-2025-58931 WordPress Palatio theme <= 1.6 - Local File Inclusion vulnerability — Palatio CWE-98 8.1 High 2025-12-18
CVE-2025-58927 WordPress Stallion theme <= 1.17 - Local File Inclusion vulnerability — Stallion CWE-98 8.1 High 2025-12-18
CVE-2025-58923 WordPress Critique theme <= 1.17 - Local File Inclusion vulnerability — Critique CWE-98 8.1 High 2025-12-18
CVE-2025-58925 WordPress Neptunus theme <= 1.0.11 - Local File Inclusion vulnerability — Neptunus CWE-98 8.1 High 2025-12-18
CVE-2025-58926 WordPress Cerebrum theme <= 1.12 - Local File Inclusion vulnerability — Cerebrum CWE-98 8.1 High 2025-12-18
CVE-2025-58894 WordPress Good Mood theme <= 1.16 - Local File Inclusion vulnerability — Good Mood CWE-98 8.1 High 2025-12-18
CVE-2025-58893 WordPress Alright theme <= 1.6.1 - Local File Inclusion vulnerability — Alright CWE-98 8.1 High 2025-12-18
CVE-2025-58889 WordPress Towny theme <= 1.16 - Local File Inclusion vulnerability — Towny CWE-98 8.1 High 2025-12-18
CVE-2025-58803 WordPress Algenix theme <= 1.0 - Local File Inclusion vulnerability — Algenix CWE-98 8.1 High 2025-12-18
CVE-2025-58225 WordPress Paragon theme <= 1.1 - Local File Inclusion vulnerability — Paragon CWE-98 8.1 High 2025-12-18
CVE-2025-58706 WordPress Woo Hoo theme <= 1.25 - Local File Inclusion vulnerability — Woo Hoo CWE-98 8.1 High 2025-12-18
CVE-2025-58708 WordPress 777 theme <= 1.3 - Local File Inclusion vulnerability — 777 CWE-98 8.1 High 2025-12-18
CVE-2025-58709 WordPress Legacy theme <= 1.9 - Local File Inclusion vulnerability — Legacy CWE-98 8.1 High 2025-12-18
CVE-2025-53449 WordPress Convex theme <= 1.11 - Local File Inclusion vulnerability — Convex CWE-98 8.1 High 2025-12-18
CVE-2025-53453 WordPress Hygia theme <= 1.16 - Local File Inclusion vulnerability — Hygia CWE-98 8.1 High 2025-12-18
CVE-2025-53448 WordPress Rally theme <= 1.1 - Local File Inclusion vulnerability — Rally CWE-98 8.1 High 2025-12-18
CVE-2025-53447 WordPress Assembly theme <= 1.1 - Local File Inclusion vulnerability — Assembly CWE-98 8.1 High 2025-12-18
CVE-2025-53446 WordPress Beautique theme <= 1.5 - Local File Inclusion vulnerability — Beautique CWE-98 8.1 High 2025-12-18
CVE-2025-53445 WordPress Catwalk theme <= 1.4 - Local File Inclusion vulnerability — Catwalk CWE-98 8.1 High 2025-12-18
CVE-2025-53442 WordPress Rentic theme <= 1.1 - Local File Inclusion vulnerability — Rentic CWE-98 8.1 High 2025-12-18
CVE-2025-53441 WordPress Greeny theme <= 2.6 - Local File Inclusion vulnerability — Greeny CWE-98 8.1 High 2025-12-18
CVE-2025-53443 WordPress Smash theme <= 1.7 - Local File Inclusion vulnerability — Smash CWE-98 8.1 High 2025-12-18
CVE-2025-53435 WordPress Plan My Day theme <= 1.1.13 - Local File Inclusion vulnerability — Plan My Day CWE-98 8.1 High 2025-12-18

This page lists every published CVE security advisory associated with axiomthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.