AivahThemes Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with AivahThemes products.
Products
- Anona3 vulnerabilities
- Car Zone2 vulnerabilities
- business_hours_pro1 vulnerability
- Hostme v21 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-69139HIGH | WordPress Car Zone theme <= 3.7 - Arbitrary File Deletion vulnerabilityUnauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions. CWE-22Jun 16, 2026 | CVSS8.6v3.1 | EPSS0.533% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27338HIGH | WordPress Car Zone theme <= 3.7 - Deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through <= 3.7. CWE-502Mar 5, 2026 | CVSS8.8v3.1 | EPSS0.381% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68907HIGH | WordPress Hostme v2 theme <= 7.0 - Arbitrary File Deletion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Hostme v2 hostmev2 allows Path Traversal.This issue affects Hostme v2: from n/a through <= 7.0. CWE-22Jan 22, 2026 | CVSS7.5v3.1 | EPSS0.371% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68903HIGH | WordPress Anona theme <= 8.0 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0. CWE-502Jan 22, 2026 | CVSS8.8v3.1 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68902HIGH | WordPress Anona theme <= 8.0 - Arbitrary File Download vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affects Anona: from n/a through <= 8.0. CWE-22Jan 22, 2026 | CVSS7.5v3.1 | EPSS0.447% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68901HIGH | WordPress Anona theme <= 8.0 - Arbitrary File Deletion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affects Anona: from n/a through <= 8.0. CWE-22Jan 22, 2026 | CVSS8.6v3.1 | EPSS0.458% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24240CRITICAL | Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCEThe Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leading to an unauthenticated remote code execution vulnerability. CWE-434Apr 22, 2021 | CVSS9.8v3.1 | EPSS3.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |