Vulnerabilities in ThemeREX

187 results
Vexday analysis

Com 183 CVEs catalogadas e 58 surgidas nos últimos 90 dias, o volume recente de vulnerabilidades nos produtos ThemeREX indica um ritmo elevado de descobertas que merece atenção contínua. Das falhas mapeadas, 24 são classificadas como críticas, embora nenhuma conste no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, e nenhuma possua PoC pública conhecida, o que reduz o risco imediato de exploração em massa. O tipo de falha mais comum é CWE-98 (Remote File Inclusion), categoria que, quando explorada, pode permitir execução remota de código e comprometimento integral de instâncias afetadas. A CVE mais perigosa ativa no momento, CVE-2024-13448, apresenta EPSS de 0,0088, sugerindo baixa probabilidade de exploração ativa no curto prazo, mas o padrão estrutural de falhas de inclusão remota recomenda priorização de correções e revisão de configurações de servidor em ambientes que utilizem temas ou plugins desse vendor.

CVE-2026-28085HIGHWordPress Mahogany theme <= 2.9 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28093HIGHWordPress Ozisti theme <= 1.1.10 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28010HIGHWordPress Scientia theme <= 1.2.4 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28007HIGHWordPress Coinpress theme <= 1.0.14 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28029HIGHWordPress EmojiNation theme <= 1.0.12 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28087HIGHWordPress Filmax theme <= 1.1.11 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28018HIGHWordPress Global Logistics theme <= 3.20 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28089HIGHWordPress Daiquiri theme <= 1.2.4 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28067HIGHWordPress Bassein theme <= 1.0.15 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28084HIGHWordPress Bazinga theme <= 1.1.9 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28045HIGHWordPress N7 | Golf Club Sports & Events theme <= 2.16.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28052HIGHWordPress Peter Mason theme <= 1.4.5 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28046HIGHWordPress Law Office theme <= 3.3.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28035HIGHWordPress Printy theme <= 1.8 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-27988HIGHWordPress Equadio theme <= 1.1.3 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-27995HIGHWordPress Justitia theme <= 1.1.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-27985HIGHWordPress Humanum theme <= 1.1.4 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28012HIGHWordPress Gridiron theme <= 1.0.14 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28090HIGHWordPress Gamezone theme <= 1.1.11 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28055HIGHWordPress M.Williamson theme <= 1.2.11 - Local File Inclusion vulnerabilityEPSS 0.4%