Browse all 4 CVE security advisories affecting Themeinwp. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Themeinwp develops WordPress themes primarily for commercial and personal websites. Historically, their themes have been associated with multiple remote code execution vulnerabilities, cross-site scripting issues, and privilege escalation flaws, often stemming from insufficient input validation and improper access controls. The 4 CVEs recorded highlight recurring security concerns, including insecure object injection and authentication bypass weaknesses. While no major public security incidents have been documented, the consistent pattern of vulnerabilities suggests a need for improved security practices in theme development and regular updates for users to mitigate potential risks.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-10051 | Demo Import Kit <= 1.1.0 - Authenticated (Admin+) Arbitrary File Upload — Demo Import KitCWE-434 | 7.2 | High | 2025-10-15 |
This page lists every published CVE security advisory associated with Themeinwp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.