Vulnerabilities in ThemeREX

187 results
Vexday analysis

Com 183 CVEs catalogadas e 58 surgidas nos últimos 90 dias, o volume recente de vulnerabilidades nos produtos ThemeREX indica um ritmo elevado de descobertas que merece atenção contínua. Das falhas mapeadas, 24 são classificadas como críticas, embora nenhuma conste no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, e nenhuma possua PoC pública conhecida, o que reduz o risco imediato de exploração em massa. O tipo de falha mais comum é CWE-98 (Remote File Inclusion), categoria que, quando explorada, pode permitir execução remota de código e comprometimento integral de instâncias afetadas. A CVE mais perigosa ativa no momento, CVE-2024-13448, apresenta EPSS de 0,0088, sugerindo baixa probabilidade de exploração ativa no curto prazo, mas o padrão estrutural de falhas de inclusão remota recomenda priorização de correções e revisão de configurações de servidor em ambientes que utilizem temas ou plugins desse vendor.

CVE-2025-69142HIGHWordPress Abelle theme <= 1.22 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28064HIGHWordPress Edge Decor theme <= 2.2 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-27992HIGHWordPress Meals & Wheels theme <= 1.1.12 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28030HIGHWordPress Bonbon theme <= 1.6 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-27997HIGHWordPress Maxify theme <= 1.0.16 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28050HIGHWordPress Beacon theme <= 2.24 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28021HIGHWordPress Craftis theme <= 1.2.8 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58954HIGHWordPress HomeRoofer theme <= 2.11.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58953HIGHWordPress Joly theme <= 1.22.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-69081HIGHWordPress Hope theme <= 3.0.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-27987HIGHWordPress The Qlean theme <= 2.12 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28051HIGHWordPress Yacht Rental theme <= 2.6 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28077HIGHWordPress Vapester theme <= 1.1.10 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28096HIGHWordPress WealthCo theme <= 2.18 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28011HIGHWordPress Yottis theme <= 1.0.10 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28060HIGHWordPress S.King theme <= 1.5.3 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28032HIGHWordPress Tuning theme <= 1.3 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-27998HIGHWordPress Vixus theme <= 1.0.16 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28081HIGHWordPress Windsor theme <= 2.5.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28043CRITICALWordPress Healer - Doctor, Clinic & Medical WordPress Theme theme <= 1.0.0 - Local File Inclusion vulnerabilityEPSS 0.4%