SecAlerts
a

athemes

Security Risk Profile

31
/100
low

Security Risk Score

Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 20, 2024 to present

13
Total CVEs
1
Critical+High
0
Exploited
1
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
31/100
low

Severity Distribution

Critical
0
High
1
Medium
12
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
7

Age Distribution

Common Weaknesses (CWE)

1
XSS
12

Most Affected Products

1. aThemes Addons for Elementor6
2. aThemes Sydney Toolbox Wordpress5
3. aThemes Athemes Addons For Elementor Wordpress4
4. WordPress aThemes Addons for Elementor2
5. aThemes Sydney Toolbox2

Recent Vulnerabilities

See more →
CVE-2026-8613
CVSS 6.4EPSS 0%medium

aThemes Addons for Elementor <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Widget Setting

Jun 10, 2026🔧 No Patch
CVE-2025-12837
CVSS 6.4medium

aThemes Addons for Elementor <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Call To Action Widget

Nov 8, 2025🔧 No Patch
CVE-2025-8149
CVSS 6.4medium

aThemes Addons for Elementor Lite <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

Sep 6, 2025🔧 No Patch
CVE-2025-32158
CVSS 8.8EPSS 0%high

WordPress aThemes Addons for Elementor plugin <= 1.1.3 - Local File Inclusion vulnerability

Apr 10, 2025🔧 No Patch
CVE-2025-22646
CVSS 6.5medium

WordPress aThemes Addons for Elementor plugin <= 1.0.8 - Stored Cross Site Scripting (XSS) vulnerability

Mar 27, 2025
CVE-2024-13547
CVSS 6.4medium

aThemes Addons for Elementor <= 1.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 1, 2025
CVE-2024-51675
CVSS 6.5medium

WordPress aThemes Addons for Elementor plugin <= 1.0.7 - Cross Site Scripting (XSS) vulnerability

Nov 9, 2024
CVE-2024-6897
CVSS 6.4EPSS 0%medium

aThemes Starter Sites <= 1.0.53 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

Jul 27, 2024🔧 No Patch
CVE-2024-4473
CVSS 6.4EPSS 0%medium

Sydney Toolbox <= 1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via aThemes: Portfolio Widget

May 14, 2024🔧 No Patch
CVE-2024-4036
CVSS 6.4EPSS 0%medium

Sydney Toolbox <= 1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 2, 2024🔧 No Patch

Monitor athemes in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

athemes Security Vulnerabilities & Risk Score | 13 CVEs | SecAlerts - SecAlerts