AivahThemes Vulnerabilities and Affected Products
Vulnerabilities associated with Hostme v2.
Products
Clear product- Anona3 vulnerabilities
- Car Zone2 vulnerabilities
- business_hours_pro1 vulnerability
- Hostme v21 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-68907HIGH | WordPress Hostme v2 theme <= 7.0 - Arbitrary File Deletion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Hostme v2 hostmev2 allows Path Traversal.This issue affects Hostme v2: from n/a through <= 7.0. CWE-22Jan 22, 2026 | CVSS7.5v3.1 | EPSS0.371% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |