AivahThemes Vulnerabilities and Affected Products
Vulnerabilities associated with Car Zone.
Products
Clear product- Anona3 vulnerabilities
- Car Zone2 vulnerabilities
- business_hours_pro1 vulnerability
- Hostme v21 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-69139HIGH | WordPress Car Zone theme <= 3.7 - Arbitrary File Deletion vulnerabilityUnauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions. CWE-22Jun 16, 2026 | CVSS8.6v3.1 | EPSS0.533% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27338HIGH | WordPress Car Zone theme <= 3.7 - Deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through <= 3.7. CWE-502Mar 5, 2026 | CVSS8.8v3.1 | EPSS0.381% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |