Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

fuelthemes — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting fuelthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Fuelthemes develops WordPress themes and plugins for website building, with 9 CVEs recorded historically. Common vulnerabilities include stored cross-site scripting (XSS) and remote code execution (RCE), often stemming from insufficient input validation and improper access controls. Privilege escalation issues have also been documented in several products. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities suggests ongoing challenges in secure coding practices. The company's products remain popular despite these security concerns, indicating that users should prioritize timely updates and implement additional security layers when using their themes and plugins.

CVE ID Title CVSS Severity Published
CVE-2026-94067 WordPress The Voux theme <= 6.9.5 - Local File Inclusion vulnerability — The Voux CWE-98 8.1 High 2026-10-09
CVE-2026-94062 WordPress Werkstatt theme <= 4.8.3 - Local File Inclusion vulnerability — Werkstatt CWE-98 8.1 High 2026-10-09
CVE-2026-57690 WordPress Werkstatt theme <= 4.7.2 - Cross Site Request Forgery (CSRF) vulnerability — Werkstatt CWE-352 4.3 Medium 2026-07-02
CVE-2026-57689 WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability — Werkstatt CWE-862 4.3 Medium 2026-07-02
CVE-2026-27414 WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability — Werkstatt CWE-502 8.8 High 2026-07-02
CVE-2026-23801 WordPress The Issue theme <= 1.6.11 - Local File Inclusion vulnerability — The Issue CWE-98 8.1 High 2026-03-05
CVE-2025-69322 WordPress PeakShops theme < 1.5.9 - Local File Inclusion vulnerability — PeakShops CWE-98 8.1 High 2026-02-20
CVE-2025-69294 WordPress PeakShops theme <= 1.5.9 - PHP Object Injection vulnerability — PeakShops CWE-502 8.8 High 2026-02-20
CVE-2025-69314 WordPress Werkstatt theme < 4.8.3 - Local File Inclusion vulnerability — Werkstatt CWE-98 8.1 High 2026-01-22
CVE-2025-69099 WordPress North theme <= 5.7.5 - PHP Object Injection vulnerability — North CWE-502 8.8 High 2026-01-22
CVE-2025-69100 WordPress North theme <= 5.7.5 - Local File Inclusion vulnerability — North CWE-98 8.1 High 2026-01-22
CVE-2025-63017 WordPress WerkStatt plugin plugin <= 1.6.6 - Local File Inclusion vulnerability — WerkStatt Plugin CWE-98 7.5 High 2026-01-22
CVE-2025-63003 WordPress North - Required Plugin plugin <= 1.4.2 - Local File Inclusion vulnerability — North - Required Plugin CWE-98 7.5 High 2025-12-09
CVE-2025-62066 WordPress Revolution theme < 2.5.8 - Local File Inclusion vulnerability — Revolution CWE-98 7.5 High 2025-11-06

This page lists every published CVE security advisory associated with fuelthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.