PatchSiren

ThemeREX Group CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL ThemeREX Group CVE published 2026-06-17

CVE-2026-39529

CVE-2026-39529 is a critical vulnerability in the Elementra theme, affecting versions up to 1.0.9. This vulnerability allows for unauthenticated PHP object injection, posing a significant risk to affected systems. With a CVSS score of 9.8, it is considered critical. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Elementra theme should take immediate actio [truncated]

HIGH ThemeREX Group CVE published 2026-06-17

CVE-2025-60085

CVE-2025-60085 is an Unauthenticated Local File Inclusion vulnerability in Learnify versions <= 1.15.0. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The CVE record was published on 2026-06-17T13:19:15.317Z and was last modified on 2026-06-17T14:45:15.717Z. This vulnerability allows unauthenticated attackers to include local files, potentially leading to data breaches or sy [truncated]

HIGH ThemeREX Group CVE published 2026-06-17

CVE-2025-58924

CVE-2025-58924 is an Unauthenticated Local File Inclusion vulnerability in Geya <= 1.15 versions. The CVE record was published on 2026-06-17T13:19:14.387Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability allows an unauthenticated attacker to include local files, potentially leading to code execution. Users of Geya theme version 1.15 or earlier should be aware o [truncated]