Vulnerabilities in ThemeREX

187 results
Vexday analysis

Com 183 CVEs catalogadas e 58 surgidas nos últimos 90 dias, o volume recente de vulnerabilidades nos produtos ThemeREX indica um ritmo elevado de descobertas que merece atenção contínua. Das falhas mapeadas, 24 são classificadas como críticas, embora nenhuma conste no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, e nenhuma possua PoC pública conhecida, o que reduz o risco imediato de exploração em massa. O tipo de falha mais comum é CWE-98 (Remote File Inclusion), categoria que, quando explorada, pode permitir execução remota de código e comprometimento integral de instâncias afetadas. A CVE mais perigosa ativa no momento, CVE-2024-13448, apresenta EPSS de 0,0088, sugerindo baixa probabilidade de exploração ativa no curto prazo, mas o padrão estrutural de falhas de inclusão remota recomenda priorização de correções e revisão de configurações de servidor em ambientes que utilizem temas ou plugins desse vendor.

CVE-2026-28023HIGHWordPress Nuts theme <= 1.10 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28056HIGHWordPress MCKinney's Politics theme <= 1.2.8 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28098HIGHWordPress Save Life theme <= 1.2.13 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28063HIGHWordPress Asia Garden theme <= 1.3.1 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28066HIGHWordPress Legrand theme <= 2.17 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28107HIGHWordPress Muzicon theme <= 1.9.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-22474CRITICALWordPress Equestrian Centre theme <= 1.5 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69127CRITICALWordPress Plumbing theme <= 1.6 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69111CRITICALWordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69079CRITICALWordPress Sound | Musical Instruments Online Store theme <= 1.6.9 - Deserialization of untrusted data vulnerabilityEPSS 0.4%CVE-2025-69405CRITICALWordPress Lorem Ipsum | Books & Media Store theme <= 1.2.11 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-27439CRITICALWordPress Dentario theme <= 1.5 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-27083CRITICALWordPress Work & Travel Company theme <= 1.2 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-28074CRITICALWordPress Pizza House theme <= 1.4.0 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-27437CRITICALWordPress Tennis Club theme <= 1.2.3 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-27082CRITICALWordPress Love Story theme <= 1.3.12 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69404CRITICALWordPress Extreme Store theme <= 1.5.10 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-27438CRITICALWordPress Kingler theme <= 1.7 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-28105CRITICALWordPress Good Energy theme <= 1.7.7 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-22331HIGHWordPress AutoParts theme <= 1.5.8 - Local File Inclusion vulnerabilityEPSS 0.4%