Vulnerabilities in axiomthemes

98 results
Vexday analysis

O portfólio de vulnerabilidades da AxiomThemes reúne 85 CVEs catalogadas, das quais 7 são classificadas como críticas — um volume que merece atenção contínua mesmo que nenhuma esteja atualmente listada no catálogo CISA KEV, mantendo a taxa de exploração ativa abaixo da média geral do catálogo. A ausência de PoCs públicas e de novas vulnerabilidades nos últimos 90 dias reduz a pressão imediata de remediação, mas não elimina o risco estrutural. O tipo de falha mais recorrente é CWE-98 (Remote File Inclusion), que historicamente permite execução de código arbitrário quando explorada com sucesso e exige controles rigorosos sobre inclusão de arquivos em ambientes PHP. A CVE mais perigosa no momento, CVE-2025-60226, apresenta EPSS de 0,0053, indicando baixa probabilidade de exploração ativa no curto prazo, mas deve ser acompanhada dado o padrão de falhas do vendor.

CVE-2025-53448HIGHWordPress Rally theme <= 1.1 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58931HIGHWordPress Palatio theme <= 1.6 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58889HIGHWordPress Towny theme <= 1.16 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-49401CRITICALWordPress smart SEO Plugin <= 4.0 - Privilege Escalation VulnerabilityEPSS 0.4%CVE-2025-58932HIGHWordPress Prisma theme <= 1.10 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-53443HIGHWordPress Smash theme <= 1.7 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58945HIGHWordPress EcoGrow theme <= 1.7 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58937HIGHWordPress Tacticool theme <= 1.0.13 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58935HIGHWordPress Lunna theme <= 1.15 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-58705HIGHWordPress Crafti theme <= 1.12 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-53440HIGHWordPress Confidant theme <= 1.4 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-22370HIGHWordPress Marveland theme <= 1.3.0 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2025-49073CRITICALWordPress Sweet Dessert < 1.1.13 - PHP Object Injection VulnerabilityEPSS 0.4%CVE-2026-27326HIGHWordPress AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme theme <= 1.2.5 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-22362HIGHWordPress Photolia theme <= 1.0.3 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28024HIGHWordPress Helion theme <= 1.1.12 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-22365HIGHWordPress Soleng theme <= 1.0.5 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-22368HIGHWordPress Redy theme <= 1.0.2 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-28079HIGHWordPress Conquerors theme <= 1.2.13 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-22364HIGHWordPress SevenTrees theme <=1.0.2 - Local File Inclusion vulnerabilityEPSS 0.4%