AivahThemes Vulnerabilities and Affected Products
Vulnerabilities associated with Anona.
Products
Clear product- Anona3 vulnerabilities
- Car Zone2 vulnerabilities
- business_hours_pro1 vulnerability
- Hostme v21 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-68903HIGH | WordPress Anona theme <= 8.0 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0. CWE-502Jan 22, 2026 | CVSS8.8v3.1 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68902HIGH | WordPress Anona theme <= 8.0 - Arbitrary File Download vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affects Anona: from n/a through <= 8.0. CWE-22Jan 22, 2026 | CVSS7.5v3.1 | EPSS0.447% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68901HIGH | WordPress Anona theme <= 8.0 - Arbitrary File Deletion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affects Anona: from n/a through <= 8.0. CWE-22Jan 22, 2026 | CVSS8.6v3.1 | EPSS0.458% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |