Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gn_themes — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting gn_themes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

gn_themes is a widely deployed WordPress theme framework utilized by numerous websites to customize visual presentation and layout. Its extensive market presence has made it a frequent target for automated scanning tools, resulting in twenty recorded Common Vulnerabilities and Exposures. The most prevalent security flaws involve cross-site scripting and SQL injection, primarily stemming from insufficient input validation in theme options and template files. Additionally, several instances of remote code execution have been identified, often linked to insecure file handling practices within the theme’s update mechanisms. While not inherently malicious, the complexity of the codebase has historically led to privilege escalation vulnerabilities that allow unauthorized administrative access. These issues highlight the risks associated with complex, third-party WordPress extensions that may not undergo rigorous security auditing, necessitating regular updates and strict input sanitization by developers to mitigate potential exploitation vectors.

Found 1 results / 20 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-3885 WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via su_box Shortcode — Shortcodes Ultimate – Content Elements CWE-79 6.4 Medium 2026-04-16

This page lists every published CVE security advisory associated with gn_themes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.