Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kutethemes — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting kutethemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kutethemes develops WordPress themes and website templates for businesses and developers. Historically, their products have frequently contained cross-site scripting (XSS) vulnerabilities, remote code execution (RCE) flaws, and privilege escalation issues, often stemming from insufficient input validation and improper access controls. While no major public security incidents have been widely documented, the 10 CVEs on record indicate a pattern of security weaknesses that could allow attackers to compromise websites, steal data, or gain unauthorized access. Users are advised to maintain regular updates and implement additional security measures when using these themes.

CVE ID Title CVSS Severity Published
CVE-2026-62115 WordPress KuteShop theme <= 4.2.9 - Local File Inclusion vulnerability — KuteShop CWE-98 8.1 High 2026-10-10
CVE-2026-62100 WordPress KuteShop theme <= 4.2.9 - Reflected Cross Site Scripting (XSS) vulnerability — KuteShop CWE-79 7.1 High 2026-10-10
CVE-2026-62098 WordPress Boutique theme <= 2.3.3 - Arbitrary Shortcode Execution vulnerability — Boutique CWE-94 6.5 Medium 2026-10-10
CVE-2026-62099 WordPress Boutique theme <= 2.3.3 - Local File Inclusion vulnerability — Boutique CWE-98 8.1 High 2026-10-10
CVE-2026-62096 WordPress Biolife theme <= 3.2.3 - Local File Inclusion vulnerability — Biolife CWE-98 8.1 High 2026-10-10
CVE-2026-62095 WordPress Biolife theme <= 3.2.3 - Reflected Cross Site Scripting (XSS) vulnerability — Biolife CWE-79 7.1 High 2026-10-10
CVE-2026-62094 WordPress TechOne theme <= 3.0.3 - Local File Inclusion vulnerability — TechOne CWE-98 8.1 High 2026-10-10
CVE-2026-62093 WordPress TechOne theme <= 3.0.3 - Reflected Cross Site Scripting (XSS) vulnerability — TechOne CWE-79 7.1 High 2026-10-10
CVE-2026-62092 WordPress Armania theme <= 1.4.8 - Local File Inclusion vulnerability — Armania CWE-98 8.1 High 2026-10-10
CVE-2026-62091 WordPress Armania theme <= 1.4.8 - Reflected Cross Site Scripting (XSS) vulnerability — Armania CWE-79 7.1 High 2026-10-10
CVE-2026-48194 WordPress DukaMarket theme <= 1.3.0 - Local File Inclusion vulnerability — DukaMarket CWE-98 8.1 High 2026-10-10
CVE-2026-48193 WordPress Uminex theme <= 1.0.9 - Local File Inclusion vulnerability — Uminex CWE-98 8.1 High 2026-10-10
CVE-2026-39628 WordPress DukaMarket theme <= 1.3.0 - Arbitrary Shortcode Execution vulnerability — DukaMarket CWE-80 5.3 Medium 2026-04-08
CVE-2026-39629 WordPress Uminex theme <= 1.0.9 - Arbitrary Shortcode Execution vulnerability — Uminex CWE-80 5.3 Medium 2026-04-08
CVE-2026-39626 WordPress Armania theme <= 1.4.8 - Arbitrary Shortcode Execution vulnerability — Armania CWE-80 5.3 Medium 2026-04-08
CVE-2026-39623 WordPress Biolife theme <= 3.2.3 - Local File Inclusion vulnerability — Biolife CWE-98 7.5 High 2026-04-08
CVE-2026-39625 WordPress TechOne theme <= 3.0.3 - Arbitrary Shortcode Execution vulnerability — TechOne CWE-80 5.3 Medium 2026-04-08
CVE-2026-39624 WordPress Biolife theme <= 3.2.3 - Arbitrary Shortcode Execution vulnerability — Biolife CWE-862 5.3 Medium 2026-04-08
CVE-2026-39613 WordPress Boutique theme <= 2.3.3 - Local File Inclusion vulnerability — Boutique CWE-98 7.5 High 2026-04-08
CVE-2026-39612 WordPress KuteShop theme <= 4.2.9 - Arbitrary Shortcode Execution vulnerability — KuteShop CWE-862 5.3 Medium 2026-04-08
CVE-2026-39611 WordPress KuteShop theme <= 4.2.9 - Local File Inclusion vulnerability — KuteShop CWE-98 7.5 High 2026-04-08
CVE-2026-25342 WordPress Boutique theme < 2.4.6 - Reflected Cross Site Scripting (XSS) vulnerability — Boutique CWE-79 7.1 High 2026-03-25

This page lists every published CVE security advisory associated with kutethemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.