Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

g5theme — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting g5theme. AI-powered Chinese analysis, POCs, and references for each vulnerability.

g5theme operates primarily as a developer of WordPress themes and plugins, catering to content creators and small businesses seeking pre-designed digital templates. Despite its market presence, the company has faced significant scrutiny due to a high volume of security flaws, with thirty-three CVEs currently documented. Historically, these vulnerabilities predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and improper sanitization of user-supplied data within plugin functionalities. These defects have allowed attackers to compromise site integrity, inject malicious scripts, or gain unauthorized administrative access. While specific large-scale breaches directly attributed to g5theme are not widely publicized, the sheer number of disclosed issues highlights systemic weaknesses in their development lifecycle. This pattern necessitates rigorous third-party auditing and immediate patching for users relying on their software to maintain robust cybersecurity postures.

Found 10 results / 34Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-32465 WordPress Essential Real Estate plugin <= 5.3.3 - PHP Object Injection vulnerability — Essential Real EstateCWE-502 8.8 High2026-08-18
CVE-2025-68071 WordPress Essential Real Estate plugin <= 5.3.2 - Insecure Direct Object References (IDOR) vulnerability — Essential Real EstateCWE-639 6.5 Medium2025-12-16
CVE-2025-66127 WordPress Essential Real Estate plugin <= 5.3.2 - Broken Access Control vulnerability — Essential Real EstateCWE-862 5.3 Medium2025-12-16
CVE-2025-48126 WordPress Essential Real Estate plugin <= 5.2.9 - Local File Inclusion vulnerability — Essential Real EstateCWE-98 8.1 High2025-06-09
CVE-2025-30849 WordPress Essential Real Estate plugin <= 5.2.0 - Local File Inclusion Vulnerability — Essential Real EstateCWE-98 8.1 High2025-04-01
CVE-2025-24698 WordPress Essential Real Estate plugin <= 5.1.8 - Cross Site Request Forgery (CSRF) vulnerability — Essential Real EstateCWE-352 4.3 Medium2025-01-24
CVE-2024-12329 Essential Real Estate <= 5.1.6 - Missing Authorization to Authenticated (Contributor+) Information Exposure — Essential Real EstateCWE-200 4.3 Medium2024-12-12
CVE-2024-4273 Essential Real Estate <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Essential Real EstateCWE-79 6.4 Medium2024-06-04
CVE-2024-4274 Essential Real Estate <= 4.4.2 - Insecure Direct Object Reference to Arbitrary Attachment Deletion — Essential Real EstateCWE-639 4.3 Medium2024-06-04
CVE-2023-6827 Essential Real Estate <= 4.3.5 - Authenticated (Subscriber+) Arbitrary File Upload — Essential Real EstateCWE-434 7.5 High2023-12-15

This page lists every published CVE security advisory associated with g5theme. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.