ThemeREX
185 tracked vulnerabilities.
CVE-2025-49890
CRITICAL
AWStats Script <0.4 - XSS
Aug 20, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-6997
MEDIUM
ThemeREX Addons <= 2.35.1.1 - Authenticated Stored Cross-Site Scripting via SVG File Upload
Jul 19, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-0837
MEDIUM
Puzzles < 4.2.6 - Authenticated Stored Cross-Site Scripting via Shortcode Attributes
Feb 13, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-0682
HIGH
ThemeREX Addons <2.33.0 - Code Injection
Jan 25, 2025
CVSS 8.8
EPSS 0.01
CVE-2024-13786
CRITICAL
Education Center WordPress Theme <= 3.6.10 - Unauthenticated PHP Object Injection
Jul 02, 2025
CVSS 9.8
EPSS 0.01
CVE-2024-13770
HIGH
Puzzles < 4.2.4 - Unauthenticated PHP Object Injection via 'view_more_posts' AJAX Action
Feb 13, 2025
CVSS 8.1
EPSS 0.01
CVE-2024-13769
MEDIUM
Puzzles < 4.2.5 - Authenticated Stored Cross-Site Scripting via theme_options_ajax_post_action
Feb 12, 2025
CVSS 6.4
EPSS 0.00
CVE-2024-13448
CRITICAL
ThemeREX Addons <2.32.3 - File Upload
Jan 28, 2025
CVSS 9.8
EPSS 0.01
CVE-2024-6297
CRITICAL
Compromised WordPress.org Plugins - Malicious Admin Creation
Jun 25, 2024
CVSS 10.0
EPSS 0.01
CVE-2020-10257
CRITICAL
NUCLEI
ThemeREX Addons < 2020-03-09 - Unauthenticated Remote Code Execution via REST API Endpoint
Mar 10, 2020
CVSS 9.8
EPSS 0.09
Products
ThemeREX Addons 4
addons 4
Puzzles | WP Magazine / Review with Store WordPress Theme + RTL 3
puzzles 3
Abelle 1
AirSupply 1
Aldo 1
Alliance 1
Aqualots 1
Artrium 1
Asia Garden 1
AutoParts 1
Avventure 1
Bassein 1
Bazinga 1
Beacon 1
Berger 1
Bonbon 1
Buisson 1
Choreo 1
Chroma 1
Classter 1
Cobble 1
Coinpress 1
Coleo 1
ConFix 1
Contact Form 7 Multi-Step Addon 1
CopyPress 1
Corbesier 1
Craftis 1
Quick Filters