8.1
CVE-2025-32286 - WordPress Butcher theme <= 2.40 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Butcher butcher allows PHP Local File Inclusion.This issue affects Butcher: from n/a through <= 2.40.
8.1
CVE-2025-32289 - WordPress Yozi theme <= 2.0.63 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Yozi yozi allows PHP Local File Inclusion.This issue affects Yozi: from n/a through <= 2.0.63.
9.8
CVE-2025-32292 - WordPress Jarvis โ Night Club, Concert, Festival WordPress theme <= 1.8.11 - PHP Object Injection Vโฆ
Deserialization of Untrusted Data vulnerability in AncoraThemes Jarvis โ Night Club, Concert, Festival WordPress jarvis allows Object Injection.This issue affects Jarvis โ Night Club, Concert, Festival WordPress: from n/a through <= 1.8.11.
8.8
CVE-2025-32293 - WordPress Finance Consultant theme <= 2.8 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant finance allows Object Injection.This issue affects Finance Consultant: from n/a through <= 2.8.
8.1
CVE-2025-32294 - WordPress Oxpitan theme <= 1.3.5 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Oxpitan oxpitan allows PHP Local File Inclusion.This issue affects Oxpitan: from n/a through <= 1.3.5.
8.1
CVE-2025-32302 - WordPress Winnex theme <= 1.3.2 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Winnex winnex allows PHP Local File Inclusion.This issue affects Winnex: from n/a through <= 1.3.2.
8.1
CVE-2025-32309 - WordPress Healsoul theme <= 2.2.3 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Healsoul healsoul allows PHP Local File Inclusion.This issue affects Healsoul: from n/a through <= 2.2.3.
9.8
CVE-2025-39480 - WordPress Car Dealer theme < 1.6.8 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer cardealer allows Object Injection.This issue affects Car Dealer: from n/a through < 1.6.8.
9.8
CVE-2025-39485 - WordPress GrandTour theme <= 5.6 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue affects Grand Tour: from n/a through <= 5.6.
9.8
CVE-2025-39489 - WordPress CouponXL theme <= 4.5.0 - Privilege Escalation Vulnerability
Incorrect Privilege Assignment vulnerability in pebas CouponXL couponxl allows Privilege Escalation.This issue affects CouponXL: from n/a through <= 4.5.0.