Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

designthemes — Vulnerabilities & Security Advisories 43

Browse all 43 CVE security advisories affecting designthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Designthemes operates primarily as a provider of web templates and themes for content management systems, targeting developers and businesses seeking pre-built digital infrastructure. Security audits have identified thirty-eight distinct Common Vulnerabilities and Exposures (CVEs) associated with its products, indicating a pattern of insufficient input validation and access control mechanisms. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Privilege Escalation, often stemming from outdated dependencies or hardcoded credentials within the theme files. These flaws typically allow attackers to execute arbitrary commands, steal session data, or bypass administrative restrictions. While no single catastrophic data breach has been publicly attributed solely to designthemes, the high volume of CVEs suggests systemic issues in their code review processes. Users are advised to apply patches immediately and restrict file permissions to mitigate the risk of exploitation.

CVE IDTitleCVSSSeverityPublished
CVE-2025-32283 WordPress Solar Energy theme <= 3.5 - PHP Object Injection Vulnerability — Solar EnergyCWE-502 8.8 High2025-10-22
CVE-2025-31072 WordPress Ofiz - Business Consulting Theme plugin <= 2.0 - Cross Site Scripting (XSS) Vulnerability — Ofiz - WordPress Business Consulting ThemeCWE-79 7.1 High2025-07-16
CVE-2025-31422 WordPress Visual Art | Gallery WordPress Theme <= 2.4 - PHP Object Injection Vulnerability — Visual Art | Gallery WordPress ThemeCWE-502 8.8 High2025-07-16
CVE-2025-31427 WordPress Invico - WordPress Consulting Business Theme <= 1.9 - Cross Site Scripting (XSS) Vulnerability — Invico - WordPress Consulting Business ThemeCWE-79 7.1 High2025-07-16
CVE-2025-52828 WordPress Red Art theme <= 3.8 - PHP Object Injection Vulnerability — Red ArtCWE-502 8.8 High2025-07-04
CVE-2025-52833 WordPress LMS theme <= 9.2 - SQL Injection Vulnerability — LMSCWE-89 9.3 Critical2025-07-04
CVE-2025-52799 WordPress LMS theme <= 9.2 - Reflected Cross Site Scripting (XSS) Vulnerability — LMSCWE-79 7.1 High2025-06-27
CVE-2025-31924 WordPress Crafts & Arts theme <= 2.5 - PHP Object Injection Vulnerability — Crafts & ArtsCWE-502 8.8 High2025-05-23
CVE-2025-32284 WordPress Pet World theme <= 2.8 - PHP Object Injection Vulnerability — Pet WorldCWE-502 8.8 High2025-05-23
CVE-2025-32293 WordPress Finance Consultant theme <= 2.8 - PHP Object Injection Vulnerability — Finance ConsultantCWE-502 8.8 High2025-05-23
CVE-2025-0845 DesignThemes Core Features <= 4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — DesignThemes Core FeaturesCWE-79 6.4 Medium2025-03-25
CVE-2024-13471 DesignThemes Core Features <= 4.7 - Missing Authorization to Unauthenticated Arbitrary File Read via dt_process_imported_file — DesignThemes Core FeaturesCWE-22 7.5 High2025-03-05
CVE-2024-13787 VEDA - MultiPurpose WordPress Theme <= 4.2 - Authenticated (Subscriber+) PHP Object Injection — VEDA - MultiPurpose WordPress ThemeCWE-502 9.8 Critical2025-03-05

This page lists every published CVE security advisory associated with designthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.