Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

posimyththemes — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting posimyththemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Posimyththemes operates as a commercial provider of WordPress themes and plugins, primarily targeting niche markets such as adult entertainment and dating platforms. This specific focus has historically attracted significant malicious attention, resulting in thirty-four recorded Common Vulnerabilities and Exposures. The most prevalent security flaws involve Remote Code Execution (RCE) and Cross-Site Scripting (XSS), often stemming from inadequate input validation and insufficient sanitization of user-supplied data within theme functions. Additionally, instances of broken access control and privilege escalation have been documented, allowing unauthorized users to manipulate site configurations or execute arbitrary scripts. These vulnerabilities frequently arise from complex, poorly audited codebases designed to handle sensitive media uploads and user interactions. While no single catastrophic data breach has been publicly attributed solely to this vendor, the high volume of CVEs indicates systemic weaknesses in their development lifecycle, posing substantial risks to any website integrating their software without rigorous security patching and monitoring.

CVE IDTitleCVSSSeverityPublished
CVE-2024-2210 The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listing — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerceCWE-22 6.4 Medium2024-03-27
CVE-2024-1419 The Plus Addons for Elementor <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting Header Meta Content Widget — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerceCWE-79 6.4 Medium2024-03-07
CVE-2021-4332 The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerceCWE-73 6.5 Medium2023-03-07
CVE-2021-4331 The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerceCWE-862 8.8 High2023-03-07

This page lists every published CVE security advisory associated with posimyththemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.