PatchSiren

Jthemes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Jthemes CVE published 2026-06-17

CVE-2025-69138

A HIGH severity vulnerability, CVE-2025-69138, was found in Genemy theme versions <= 1.6.6. This vulnerability allows for subscriber privilege escalation with a CVSS score of 8.8. The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Users of Genemy theme versions <= 1.6.6 should be aware of this HIGH severity vulnerability and take necessary actions to mitigate the risk. Th [truncated]

MEDIUM Jthemes CVE published 2026-06-17

CVE-2025-69137

A medium-severity vulnerability, CVE-2025-69137, was discovered in the Genemy theme, affecting versions <= 1.6.6. This vulnerability is related to broken access control, potentially allowing unauthorized access to subscriber data. The CVSS score for this vulnerability is 6.5, indicating a medium level of severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users o [truncated]