ThemeREX

185 tracked vulnerabilities.

CVE-2025-49890 CRITICAL
AWStats Script <0.4 - XSS
Aug 20, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-6997 MEDIUM
ThemeREX Addons <= 2.35.1.1 - Authenticated Stored Cross-Site Scripting via SVG File Upload
Jul 19, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-0837 MEDIUM
Puzzles < 4.2.6 - Authenticated Stored Cross-Site Scripting via Shortcode Attributes
Feb 13, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-0682 HIGH
ThemeREX Addons <2.33.0 - Code Injection
Jan 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2024-13786 CRITICAL
Education Center WordPress Theme <= 3.6.10 - Unauthenticated PHP Object Injection
Jul 02, 2025
CVSS 9.8
EPSS 0.01
CVE-2024-13770 HIGH
Puzzles < 4.2.4 - Unauthenticated PHP Object Injection via 'view_more_posts' AJAX Action
Feb 13, 2025
CVSS 8.1
EPSS 0.01
CVE-2024-13769 MEDIUM
Puzzles < 4.2.5 - Authenticated Stored Cross-Site Scripting via theme_options_ajax_post_action
Feb 12, 2025
CVSS 6.4
EPSS 0.00
CVE-2024-13448 CRITICAL
ThemeREX Addons <2.32.3 - File Upload
Jan 28, 2025
CVSS 9.8
EPSS 0.01
CVE-2024-6297 CRITICAL
Compromised WordPress.org Plugins - Malicious Admin Creation
Jun 25, 2024
CVSS 10.0
EPSS 0.01
CVE-2020-10257 CRITICAL NUCLEI
ThemeREX Addons < 2020-03-09 - Unauthenticated Remote Code Execution via REST API Endpoint
Mar 10, 2020
CVSS 9.8
EPSS 0.09