Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Elated-Themes — Vulnerabilities & Security Advisories 49

Browse all 49 CVE security advisories affecting Elated-Themes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Elated-Themes operates as a software vendor specializing in digital themes and plugins, primarily targeting content management systems. Historical security audits reveal a pattern of critical vulnerabilities, with thirty-one Common Vulnerabilities and Exposures (CVEs) currently documented. The most prevalent flaw types include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation, indicating systemic weaknesses in input validation and access control mechanisms. These defects often stem from insufficient sanitization of user-supplied data and improper handling of administrative functions. While specific major incidents involving widespread exploitation are not explicitly detailed in public records, the high volume of disclosed CVEs suggests a consistent history of security lapses. This profile highlights the necessity for rigorous code review and proactive patch management to mitigate the inherent risks associated with the vendor’s software ecosystem.

CVE IDTitleCVSSSeverityPublished
CVE-2026-57793 WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability — FlowCWE-98 7.5 High2026-07-13
CVE-2026-42382 WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability — AudreyCWE-98 8.1 High2026-07-02
CVE-2026-39576 WordPress SingleMalt theme <= 1.5 - PHP Object Injection vulnerability — SingleMaltCWE-502 8.1 High2026-06-17
CVE-2026-39556 WordPress Konsept theme <= 1.9 - PHP Object Injection vulnerability — KonseptCWE-502 8.1 High2026-06-17
CVE-2026-39523 WordPress Solene Core plugin <= 2.3.2 - Local File Inclusion vulnerability — Solene CoreCWE-98 8.1 High2026-06-17
CVE-2026-39558 WordPress Malmö theme <= 2.2 - Local File Inclusion vulnerability — MalmöCWE-98 8.1 High2026-06-17
CVE-2026-40758 WordPress Léonie theme <= 1.2.1 - PHP Object Injection vulnerability — LéonieCWE-502 8.1 High2026-06-16
CVE-2026-40754 WordPress Roisin theme <= 1.4 - PHP Object Injection vulnerability — RoisinCWE-502 8.1 High2026-06-16
CVE-2026-39578 WordPress Valiance theme <= 1.2 - PHP Object Injection vulnerability — ValianceCWE-502 8.1 Medium2026-06-16
CVE-2026-39568 WordPress Mr. SEO theme <= 2.0 - Local File Inclusion vulnerability — Mr. SEOCWE-98 8.1 High2026-06-16
CVE-2026-39577 WordPress Playroom theme <= 1.4.1 - PHP Object Injection vulnerability — PlayroomCWE-502 8.1 Medium2026-06-16
CVE-2026-39554 WordPress Fidalgo theme <= 1.2.2 - PHP Object Injection vulnerability — FidalgoCWE-502 8.1 High2026-06-16
CVE-2026-39557 WordPress NeoBeat theme <= 1.7 - PHP Object Injection vulnerability — NeoBeatCWE-502 8.1 High2026-06-16
CVE-2026-39549 WordPress Aperitif theme <= 1.5 - Local File Inclusion vulnerability — AperitifCWE-98 8.1 High2026-06-16
CVE-2026-39522 WordPress Solene theme <= 3.4 - Local File Inclusion vulnerability — SoleneCWE-98 8.1 High2026-06-16
CVE-2026-39555 WordPress Askka theme <= 1.3.1 - PHP Object Injection vulnerability — AskkaCWE-502 8.1 High2026-06-02
CVE-2026-39551 WordPress Töbel theme <= 1.8.1 - PHP Object Injection vulnerability — TöbelCWE-502 8.1 High2026-06-02
CVE-2026-39550 WordPress Aperitif theme <= 1.6 - PHP Object Injection vulnerability — AperitifCWE-502 8.1 High2026-06-02
CVE-2026-32507 WordPress Leroux theme < 1.4 - Arbitrary Object Instantiation vulnerability — LerouxCWE-502 5.4 Medium2026-03-25
CVE-2026-27048 WordPress The Aisle Core plugin <= 2.0.5 - Local File Inclusion vulnerability — The Aisle CoreCWE-98 8.1 High2026-03-25
CVE-2026-24972 WordPress Elated Listing plugin <= 1.4 - Broken Access Control vulnerability — Elated ListingCWE-862 6.5 Medium2026-03-25
CVE-2026-24971 WordPress Search & Go theme <= 2.8 - Privilege Escalation vulnerability — Search & GoCWE-266 9.8 Critical2026-03-25
CVE-2026-22511 WordPress NeoBeat theme <= 1.2 - Local File Inclusion vulnerability — NeoBeatCWE-98 8.1 High2026-03-25
CVE-2026-22512 WordPress Roisin theme <= 1.2.1 - Local File Inclusion vulnerability — RoisinCWE-98 8.1 High2026-03-25
CVE-2026-22506 WordPress Amoli theme <= 1.0 - Local File Inclusion vulnerability — AmoliCWE-98 8.1 High2026-03-25
CVE-2026-22509 WordPress Gioia theme <= 1.4 - Local File Inclusion vulnerability — GioiaCWE-98 8.1 High2026-03-25
CVE-2026-22498 WordPress Laurent theme <= 3.1 - Local File Inclusion vulnerability — LaurentCWE-98 8.1 High2026-03-25
CVE-2026-22499 WordPress Lella theme <= 1.2 - Local File Inclusion vulnerability — LellaCWE-98 8.1 High2026-03-25
CVE-2026-22493 WordPress Gaspard theme <= 1.3 - Local File Inclusion vulnerability — GaspardCWE-98 8.1 High2026-03-25
CVE-2026-22478 WordPress FindAll theme <= 1.4 - Local File Inclusion vulnerability — FindAllCWE-98 8.1 High2026-03-05

This page lists every published CVE security advisory associated with Elated-Themes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.