Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · themerex

themerex

· 2 Critical

Total CVEs

7

Critical

2

Products

64

Search All CVEs →

7

Products (64)

addons4 CVEspuzzles3 CVEsamuli1 CVEsblabber1 CVEsbonkozoo zoo1 CVEsbriny-diving wordpress theme1 CVEsbugster-pests control1 CVEsbuzz stone-magazine \& blog1 CVEschainpress1 CVEschit club-board games1 CVEscoinpress-cryptocurrency magazine \& blog wordpress theme1 CVEscorredo sport event1 CVEsdronex-aerial photography services1 CVEsespecio-food gutenberg theme1 CVEsfc united-football1 CVEsgloss blog1 CVEsgridiron1 CVEshallelujah-church1 CVEsheaven 11-multiskin property theme1 CVEshelion-agency \&portfolio1 CVEshobo digital nomad blog1 CVEsimpacto patronus multi-landing1 CVEsjustitia-multiskin lawyer theme1 CVEskargo-freight transport1 CVEskatelyn-gutenberg wordpress blog theme1 CVEskids care1 CVEskratz-digital agency1 CVEslingvico-language learning school1 CVEsmaxify-startup blog1 CVEsmeals and wheels-food truck1 CVEsmodern housewife-housewife and family blog1 CVEsmystik-esoterics1 CVEsnazareth-church1 CVEsnelson-barbershop \+ tattoo salon1 CVEsnetmix-broadband \& telecom1 CVEsozeum-museum1 CVEspartiso electioncampaign1 CVEspiqes-creative startup \& agency wordpress theme1 CVEspixefy1 CVEsplumbing-repair\, building \& construction wordpress theme1 CVEsprider-pride fest1 CVEsrare radio1 CVEsrenewal-plastic surgeon clinic1 CVEsrhodos-creative corporate wordpress theme1 CVEsright way1 CVEsrosalinda-vegetarian \& health coach1 CVEsrumble-single fighter boxer\, news\, gym\, store1 CVEssamadhi-buddhist1 CVEssavejulia personal fundraising campaign1 CVEsscientia-public library1 CVEsskydiving and flying company1 CVEstacticool-shooting range wordpress theme1 CVEstantum-rent a car\, rent a bike\, rent a scooter multiskin theme1 CVEstediss-soft play area\, cafe \& child care center1 CVEstopper theme and skins1 CVEstornados1 CVEsvapester1 CVEsvihara-ashram\, buddhist1 CVEsvixus-startup \/ mobile application1 CVEswellspring water filter systems1 CVEsyolox-startup magazine \& blog wordpress theme1 CVEsyottis-simple portfolio1 CVEsyungen-digital\/marketing agency1 CVEsaldo-gutenberg wordpress blog theme1 CVEs

Recent Vulnerabilities

View all 7
CVE-2025-6997MEDIUM 6.4

The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.35.1.1 due to insufficient input sanitization and output escaping. The plugin’s SVG rendering routine calls the trx_addons_get_svg_from_file() function on an unvalidated 'svg' parameter supplied via the shortcode or Elementor widget settings, then outputs it via the trx_addons_show_layout() function. Because there is no check on the URL’s origin, scheme, or the SVG content itself, authenticated attackers, with Contributor-level access and above, can supply a remote SVG and inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVE-2025-0837MEDIUM 6.4

The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-13770HIGH 8.1

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2.4 via deserialization of untrusted input 'view_more_posts' AJAX action. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. The developer opted to remove the software from the repository, so an update is not available and it is recommended to find a replacement software.

CVE-2024-13769MEDIUM 6.4

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the 'theme_options_ajax_post_action' AJAX action in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings and inject malicious web scripts. The developer opted to remove the software from the repository, so an update is not available and it is recommended to find a replacement software.

CVE-2024-13448CRITICAL 9.8

The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-0682HIGH 8.8

The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.0 via the 'trx_sc_reviews' shortcode 'type' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

CVE-2020-10257CRITICAL 9.8

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.