Vendor
Themeum vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 25 vulnerabilities in Themeum: 0 in the last 7 days and 18 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-92465, was published on 16 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 18
- Critical, all time
- 3
- Exploited in the wild
- 0
About Themeum
A software company that develops WordPress themes and plugins, including the Tutor LMS platform.
Themeum technologies
Latest Themeum vulnerabilities
- CVE-2026-92465: Themeum WP Mega Menu SQL injectionhighCVSS 7.6EPSS 0.4%
- CVE-2026-85569: Tutor LMS privilege escalation via REST API request misclassificationhighCVSS 7.2EPSS 0.5%
- CVE-2026-78175: Tutor LMS PHP Object Injection in withdraw method handlerhighCVSS 8.8EPSS 1.1%
- CVE-2026-19092: Tutor LMS plugin arbitrary function invocation in template renderingcriticalCVSS 9.8EPSS 2.0%
- CVE-2026-14310: Themeum Tutor LMS IDOR in Q&A threadsinfoCVSS 5.4
- CVE-2026-15444: Themeum Tutor LMS SQL injection in coupon_codemediumCVSS 4.9
- CVE-2026-65436: Themeum Kirki arbitrary file deletion in Editor componentmediumCVSS 6.8
- CVE-2026-65531: Themeum Qubely broken access controlmediumCVSS 4.8
- CVE-2026-1372: Themeum Tutor LMS Elementor Addons missing authorization in plugin activationmediumCVSS 4.3
- CVE-2026-15022: Themeum Tutor LMS SQL injection in Stored Quiz Answer ArraymediumCVSS 6.5
- CVE-2026-57727: Themeum Kirki missing authorization in access controlhighCVSS 7.5
- CVE-2026-57726: Themeum Kirki blind SQL injectioncriticalCVSS 9.3
- CVE-2026-57694: Themeum Tutor LMS IDOR authorization bypassmediumCVSS 6.5
- CVE-2026-12275: Themeum Tutor LMS auth bypass in Droip and Kirki integrationsinfoCVSS 5.4
- CVE-2026-12274: Tutor LMS IDOR in content-builder save handlerinfoCVSS 8.8
- CVE-2026-12273: Themeum Tutor LMS authorization bypass in comment handlerinfoCVSS 4.3
- CVE-2026-12271: Themeum Tutor LMS IDOR in quiz attempt modificationinfoCVSS 5.4
- CVE-2026-13443: Themeum Tutor LMS stored XSS in Lesson Attachment TitlemediumCVSS 6.4
- CVE-2026-10736: Themeum Tutor LMS SQL injection in data parametermediumCVSS 4.9EPSS 0.4%
- CVE-2026-22332: Themeum Tutor LMS Pro unauthenticated SQL injectioncriticalCVSS 9.3
- CVE-2026-22330: Themeum Right Way local file inclusionhighCVSS 8.1
- CVE-2026-22329: Themeum Skillate unauthenticated XSS in WordPress themehighCVSS 7.1
- CVE-2026-40743: Themeum Tutor LMS broken access controlmediumCVSS 6.5
- CVE-2026-6965: Themeum Tutor LMS IDOR in get_course_id_by functionmediumCVSS 5.3
- CVE-2026-39638: Themeum Qubely Stored XSS in WordPress pluginmediumCVSS 5.9EPSS 0.2%
Most severe Themeum vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-19092: Tutor LMS plugin arbitrary function invocation in template renderingcriticalCVSS 9.8EPSS 2.0%
- CVE-2026-57726: Themeum Kirki blind SQL injectioncriticalCVSS 9.3
- CVE-2026-22332: Themeum Tutor LMS Pro unauthenticated SQL injectioncriticalCVSS 9.3
- CVE-2026-78175: Tutor LMS PHP Object Injection in withdraw method handlerhighCVSS 8.8EPSS 1.1%
- CVE-2026-22330: Themeum Right Way local file inclusionhighCVSS 8.1
- CVE-2026-92465: Themeum WP Mega Menu SQL injectionhighCVSS 7.6EPSS 0.4%
- CVE-2026-57727: Themeum Kirki missing authorization in access controlhighCVSS 7.5
- CVE-2026-85569: Tutor LMS privilege escalation via REST API request misclassificationhighCVSS 7.2EPSS 0.5%
- CVE-2026-22329: Themeum Skillate unauthenticated XSS in WordPress themehighCVSS 7.1
- CVE-2026-65436: Themeum Kirki arbitrary file deletion in Editor componentmediumCVSS 6.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 8 | 1 | |
| 20 Jul 2026 | 2 | 0 | |
| 27 Jul 2026 | 3 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 1 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/themeum.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Themeum vulnerabilities", https://junglewise.ai/threats/vendors/themeum, 26 September 2026.