Browse all 7 CVE security advisories affecting jwsthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Jwsthemes develops WordPress themes and templates for website creation and customization. Historically, these themes have been vulnerable to multiple security issues including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities, often stemming from insufficient input validation and improper access controls. The themes have accumulated 7 CVE records, with several critical flaws allowing attackers to execute arbitrary code or compromise user accounts. Security researchers have identified consistent patterns in their codebase that leave installations exposed, particularly in areas handling file uploads and user permissions. No major public security incidents have been widely reported, though the CVE count indicates a persistent security challenge requiring ongoing vigilance from users.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-69087 | WordPress FreeAgent theme <= 2.1.2 - Local File Inclusion vulnerability — FreeAgentCWE-98 | 8.1 | High | 2026-01-05 |
This page lists every published CVE security advisory associated with jwsthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.