{"schema_version":1,"title":"ThemeREX vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 63 vulnerabilities in ThemeREX: 0 in the last 7 days and 2 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-57747, was published on 2 July 2026.","url":"https://junglewise.ai/threats/vendors/themerex","json_url":"https://junglewise.ai/threats/vendors/themerex.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/themerex","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":56,"all_time":63,"critical":6,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":63},"latest":[{"cve":"CVE-2026-57747","cvss":6.5,"slug":"cve-2026-57747-themerex-booked-csrf-in-wordpress-plugin","title":"ThemeREX Booked CSRF in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-07-02T12:17:40.41+00:00","url":"https://junglewise.ai/threats/cve-2026-57747-themerex-booked-csrf-in-wordpress-plugin"},{"cve":"CVE-2026-57746","cvss":7.1,"slug":"cve-2026-57746-themerex-booked-broken-access-control-in-wordpress-plugin","title":"ThemeREX Booked broken access control in WordPress plugin","severity":"high","exploited":false,"published_at":"2026-07-02T12:17:40.29+00:00","url":"https://junglewise.ai/threats/cve-2026-57746-themerex-booked-broken-access-control-in-wordpress-plugin"},{"cve":"CVE-2025-69175","cvss":8.1,"epss":0.0035,"slug":"cve-2025-69175-themerex-line-agency-local-file-inclusion","title":"ThemeREX Line Agency Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:35.79+00:00","url":"https://junglewise.ai/threats/cve-2025-69175-themerex-line-agency-local-file-inclusion"},{"cve":"CVE-2025-69174","cvss":8.1,"epss":0.0035,"slug":"cve-2025-69174-themerex-etude-local-file-inclusion","title":"ThemeREX Etude Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:35.63+00:00","url":"https://junglewise.ai/threats/cve-2025-69174-themerex-etude-local-file-inclusion"},{"cve":"CVE-2025-69170","cvss":8.1,"epss":0.0035,"slug":"cve-2025-69170-themerex-eventicity-local-file-inclusion","title":"ThemeREX Eventicity Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:35.22+00:00","url":"https://junglewise.ai/threats/cve-2025-69170-themerex-eventicity-local-file-inclusion"},{"cve":"CVE-2025-69166","cvss":8.1,"epss":0.0044,"slug":"cve-2025-69166-themerex-gunslinger-local-file-inclusion","title":"ThemeREX Gunslinger Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:35.07+00:00","url":"https://junglewise.ai/threats/cve-2025-69166-themerex-gunslinger-local-file-inclusion"},{"cve":"CVE-2025-69164","cvss":8.1,"epss":0.0035,"slug":"cve-2025-69164-themerex-skyward-unauthenticated-local-file-inclusion","title":"ThemeREX Skyward unauthenticated local file inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:34.923+00:00","url":"https://junglewise.ai/threats/cve-2025-69164-themerex-skyward-unauthenticated-local-file-inclusion"},{"cve":"CVE-2025-69158","cvss":8.1,"epss":0.0035,"slug":"cve-2025-69158-themerex-granola-unauthenticated-local-file-inclusion","title":"ThemeREX Granola unauthenticated local file inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:34.777+00:00","url":"https://junglewise.ai/threats/cve-2025-69158-themerex-granola-unauthenticated-local-file-inclusion"},{"cve":"CVE-2025-69157","cvss":8.1,"epss":0.0044,"slug":"cve-2025-69157-themerex-gamic-local-file-inclusion","title":"ThemeREX Gamic Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:34.617+00:00","url":"https://junglewise.ai/threats/cve-2025-69157-themerex-gamic-local-file-inclusion"},{"cve":"CVE-2025-69144","cvss":8.1,"epss":0.0035,"slug":"cve-2025-69144-themerex-preservation-unauthenticated-local-file-inclusion","title":"ThemeREX Preservation unauthenticated Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:34.34+00:00","url":"https://junglewise.ai/threats/cve-2025-69144-themerex-preservation-unauthenticated-local-file-inclusion"},{"cve":"CVE-2025-69127","cvss":9.8,"epss":0.0039,"slug":"cve-2025-69127-themerex-plumbing-php-object-injection","title":"ThemeREX Plumbing PHP Object Injection","severity":"critical","exploited":false,"published_at":"2026-06-17T14:17:33.46+00:00","url":"https://junglewise.ai/threats/cve-2025-69127-themerex-plumbing-php-object-injection"},{"cve":"CVE-2025-69126","cvss":8.1,"epss":0.0035,"slug":"cve-2025-69126-themerex-fortius-unauthenticated-local-file-inclusion","title":"ThemeREX Fortius unauthenticated local file inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:33.17+00:00","url":"https://junglewise.ai/threats/cve-2025-69126-themerex-fortius-unauthenticated-local-file-inclusion"},{"cve":"CVE-2025-69123","cvss":8.1,"epss":0.0035,"slug":"cve-2025-69123-themerex-snow-club-local-file-inclusion","title":"ThemeREX Snow Club Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:32.927+00:00","url":"https://junglewise.ai/threats/cve-2025-69123-themerex-snow-club-local-file-inclusion"},{"cve":"CVE-2025-69120","cvss":8.1,"epss":0.0044,"slug":"cve-2025-69120-themerex-dazzle-local-file-inclusion","title":"ThemeREX Dazzle Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:32.47+00:00","url":"https://junglewise.ai/threats/cve-2025-69120-themerex-dazzle-local-file-inclusion"},{"cve":"CVE-2025-69115","cvss":8.1,"epss":0.0035,"slug":"cve-2025-69115-themerex-luxmed-local-file-inclusion","title":"ThemeREX LuxMed Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:32.283+00:00","url":"https://junglewise.ai/threats/cve-2025-69115-themerex-luxmed-local-file-inclusion"},{"cve":"CVE-2025-69111","cvss":9.8,"epss":0.0039,"slug":"cve-2025-69111-themerex-reisen-php-object-injection","title":"ThemeREX Reisen PHP Object Injection","severity":"critical","exploited":false,"published_at":"2026-06-17T14:17:32.137+00:00","url":"https://junglewise.ai/threats/cve-2025-69111-themerex-reisen-php-object-injection"},{"cve":"CVE-2025-69106","cvss":8.1,"epss":0.0044,"slug":"cve-2025-69106-themerex-imba-local-file-inclusion","title":"ThemeREX Imba Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T14:17:31.797+00:00","url":"https://junglewise.ai/threats/cve-2025-69106-themerex-imba-local-file-inclusion"},{"cve":"CVE-2026-39529","cvss":9.8,"epss":0.0051,"slug":"cve-2026-39529-themerex-group-elementra-php-object-injection","title":"ThemeREX Group Elementra PHP object injection","severity":"critical","exploited":false,"published_at":"2026-06-17T13:20:18.777+00:00","url":"https://junglewise.ai/threats/cve-2026-39529-themerex-group-elementra-php-object-injection"},{"cve":"CVE-2026-22338","cvss":8.1,"slug":"cve-2026-22338-themerex-ecoblue-local-file-inclusion","title":"ThemeREX EcoBlue local file inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T13:20:08.49+00:00","url":"https://junglewise.ai/threats/cve-2026-22338-themerex-ecoblue-local-file-inclusion"},{"cve":"CVE-2026-22331","cvss":8.1,"slug":"cve-2026-22331-themerex-autoparts-local-file-inclusion","title":"ThemeREX AutoParts local file inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T13:20:07.94+00:00","url":"https://junglewise.ai/threats/cve-2026-22331-themerex-autoparts-local-file-inclusion"},{"cve":"CVE-2025-69176","cvss":8.1,"epss":0.0044,"slug":"cve-2025-69176-themerex-itactics-local-file-inclusion","title":"ThemeREX ITactics Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:25.003+00:00","url":"https://junglewise.ai/threats/cve-2025-69176-themerex-itactics-local-file-inclusion"},{"cve":"CVE-2025-69173","cvss":8.1,"slug":"cve-2025-69173-themerex-tipsy-local-file-inclusion","title":"ThemeREX Tipsy Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:24.87+00:00","url":"https://junglewise.ai/threats/cve-2025-69173-themerex-tipsy-local-file-inclusion"},{"cve":"CVE-2025-69172","cvss":8.1,"slug":"cve-2025-69172-themerex-resurs-unauthenticated-local-file-inclusion","title":"ThemeREX Resurs unauthenticated local file inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:24.743+00:00","url":"https://junglewise.ai/threats/cve-2025-69172-themerex-resurs-unauthenticated-local-file-inclusion"},{"cve":"CVE-2025-69171","cvss":8.1,"slug":"cve-2025-69171-themerex-orpheus-local-file-inclusion-in-wordpress-theme","title":"ThemeREX Orpheus Local File Inclusion in WordPress theme","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:24.61+00:00","url":"https://junglewise.ai/threats/cve-2025-69171-themerex-orpheus-local-file-inclusion-in-wordpress-theme"},{"cve":"CVE-2025-69168","cvss":8.1,"epss":0.0047,"slug":"cve-2025-69168-themerex-spike-local-file-inclusion-in-wordpress-theme","title":"ThemeREX Spike Local File Inclusion in WordPress theme","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:24.47+00:00","url":"https://junglewise.ai/threats/cve-2025-69168-themerex-spike-local-file-inclusion-in-wordpress-theme"}],"vendor":{"hub":true,"name":"ThemeREX","slug":"themerex","homepage":"https://themerex.net/","description":"ThemeREX is a developer of themes and plugins for the WordPress content management system.","url":"https://junglewise.ai/threats/vendors/themerex"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-69122","cvss":9.8,"epss":0.0056,"slug":"cve-2025-69122-themerex-seafood-company-php-object-injection","title":"ThemeREX SeaFood Company PHP object injection","severity":"critical","exploited":false,"published_at":"2026-06-17T13:19:18.19+00:00","url":"https://junglewise.ai/threats/cve-2025-69122-themerex-seafood-company-php-object-injection"},{"cve":"CVE-2025-69108","cvss":9.8,"epss":0.0053,"slug":"cve-2025-69108-themerex-hot-coffee-php-object-injection","title":"ThemeREX Hot Coffee PHP Object Injection","severity":"critical","exploited":false,"published_at":"2026-06-17T13:19:16.683+00:00","url":"https://junglewise.ai/threats/cve-2025-69108-themerex-hot-coffee-php-object-injection"},{"cve":"CVE-2026-39529","cvss":9.8,"epss":0.0051,"slug":"cve-2026-39529-themerex-group-elementra-php-object-injection","title":"ThemeREX Group Elementra PHP object injection","severity":"critical","exploited":false,"published_at":"2026-06-17T13:20:18.777+00:00","url":"https://junglewise.ai/threats/cve-2026-39529-themerex-group-elementra-php-object-injection"},{"cve":"CVE-2025-69127","cvss":9.8,"epss":0.0039,"slug":"cve-2025-69127-themerex-plumbing-php-object-injection","title":"ThemeREX Plumbing PHP Object Injection","severity":"critical","exploited":false,"published_at":"2026-06-17T14:17:33.46+00:00","url":"https://junglewise.ai/threats/cve-2025-69127-themerex-plumbing-php-object-injection"},{"cve":"CVE-2025-69111","cvss":9.8,"epss":0.0039,"slug":"cve-2025-69111-themerex-reisen-php-object-injection","title":"ThemeREX Reisen PHP Object Injection","severity":"critical","exploited":false,"published_at":"2026-06-17T14:17:32.137+00:00","url":"https://junglewise.ai/threats/cve-2025-69111-themerex-reisen-php-object-injection"},{"cve":"CVE-2025-60205","cvss":9.8,"slug":"cve-2025-60205-themerex-addons-php-object-injection","title":"ThemeREX Addons PHP Object Injection","severity":"critical","exploited":false,"published_at":"2026-06-17T13:19:15.457+00:00","url":"https://junglewise.ai/threats/cve-2025-60205-themerex-addons-php-object-injection"},{"cve":"CVE-2025-69168","cvss":8.1,"epss":0.0047,"slug":"cve-2025-69168-themerex-spike-local-file-inclusion-in-wordpress-theme","title":"ThemeREX Spike Local File Inclusion in WordPress theme","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:24.47+00:00","url":"https://junglewise.ai/threats/cve-2025-69168-themerex-spike-local-file-inclusion-in-wordpress-theme"},{"cve":"CVE-2025-69167","cvss":8.1,"epss":0.0047,"slug":"cve-2025-69167-themerex-eros-theme-local-file-inclusion","title":"ThemeREX Eros Theme Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:24.337+00:00","url":"https://junglewise.ai/threats/cve-2025-69167-themerex-eros-theme-local-file-inclusion"},{"cve":"CVE-2025-69165","cvss":8.1,"epss":0.0047,"slug":"cve-2025-69165-themerex-choreo-local-file-inclusion-in-wordpress-theme","title":"ThemeREX Choreo local file inclusion in WordPress theme","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:24.173+00:00","url":"https://junglewise.ai/threats/cve-2025-69165-themerex-choreo-local-file-inclusion-in-wordpress-theme"},{"cve":"CVE-2025-69163","cvss":8.1,"epss":0.0047,"slug":"cve-2025-69163-themerex-wineshop-local-file-inclusion","title":"ThemeREX WineShop Local File Inclusion","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:24.013+00:00","url":"https://junglewise.ai/threats/cve-2025-69163-themerex-wineshop-local-file-inclusion"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[]}