Vulnerabilidades en ThemeREX

187 resultados
Análisis Vexday

Com 183 CVEs catalogadas e 58 surgidas nos últimos 90 dias, o volume recente de vulnerabilidades nos produtos ThemeREX indica um ritmo elevado de descobertas que merece atenção contínua. Das falhas mapeadas, 24 são classificadas como críticas, embora nenhuma conste no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, e nenhuma possua PoC pública conhecida, o que reduz o risco imediato de exploração em massa. O tipo de falha mais comum é CWE-98 (Remote File Inclusion), categoria que, quando explorada, pode permitir execução remota de código e comprometimento integral de instâncias afetadas. A CVE mais perigosa ativa no momento, CVE-2024-13448, apresenta EPSS de 0,0088, sugerindo baixa probabilidade de exploração ativa no curto prazo, mas o padrão estrutural de falhas de inclusão remota recomenda priorização de correções e revisão de configurações de servidor em ambientes que utilizem temas ou plugins desse vendor.

CVE-2024-6297CRITICALSeveral WordPress.org Plugins <= Various Versions - Injected BackdoorEPSS 1.0%CVE-2024-13448CRITICALThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_dataEPSS 0.9%CVE-2024-13770HIGHPuzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2025-0682HIGHThemeREX Addons <= 2.33.0 - Authenticated (Contributor+) Local File Inclusion via ShortcodeEPSS 0.6%CVE-2025-69395HIGHWordPress Gable theme <= 1.5 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-69402HIGHWordPress R&F theme <= 1.5 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-60205CRITICALWordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-69122CRITICALWordPress SeaFood Company theme <= 1.4 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-69108CRITICALWordPress Hot Coffee theme <= 1.7 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2024-13786CRITICALEducation Center | LMS & Online Courses WordPress Theme <= 3.6.10 - PHP Object InjectionEPSS 0.5%CVE-2025-69398HIGHWordPress Plank theme <= 1.7 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-69400HIGHWordPress Yokoo theme <= 1.1.11 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-69406HIGHWordPress FreightCo theme <= 1.1.7 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-69397HIGHWordPress Tint theme <= 1.7 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-69396HIGHWordPress Splendour theme <= 1.23 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-69399HIGHWordPress Cobble theme <= 1.7 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-54001CRITICALWordPress Classter theme <= 2.5 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2026-22453CRITICALWordPress Pets Club theme <= 2.3 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2026-22454CRITICALWordPress Solaris theme <= 2.5 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2026-22503HIGHWordPress Nelson theme <= 1.2.0 - Local File Inclusion vulnerabilityEPSS 0.5%