Vulnerabilities in Jthemes
13 resultsVexday analysis
Jthemes apresenta 13 vulnerabilidades documentadas, com 1 crítica e 3 publicadas recentemente, mas nenhuma sob exploração ativa conforme dados KEV. O risco principal é a falha de controle de acesso (CWE-862), típica de componentes de temas, que pode permitir acesso não autorizado a funcionalidades sensíveis. Apesar do volume moderado, a ausência de ataques confirmados sugere que a exposição prática ainda é limitada.
CVE-2025-50007HIGHWordPress xSmart theme <= 1.2.9.4 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-69138HIGHWordPress Genemy theme <= 1.6.6 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-69329CRITICALWordPress Prestige theme < 1.4.1 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-59134HIGHWordPress Sale! Immigration law, Visa services support, Migration Agent Consulting theme <= 1.5.8 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-69137MEDIUMWordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-69393HIGHWordPress Exzo theme <= 1.2.4 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-54002MEDIUMWordPress xSmart theme <= 1.2.9.4 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-58243MEDIUMWordPress imEvent Theme <= 3.4.0 - Broken Access Control VulnerabilityEPSS 0.2%CVE-2025-62936MEDIUMWordPress xSmart theme <= 1.2.9.4 - Content Injection vulnerabilityEPSS 0.2%CVE-2025-50006HIGHWordPress xSmart theme <= 1.2.9.4 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-69330HIGHWordPress Prestige theme < 1.4.1 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-52747HIGHWordPress Themebox - Digital Products Ecommerce theme <= 1.4.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-59138MEDIUMWordPress Genemy theme <= 1.6.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%