theme

Aihub Vulnerabilities

6 known security issues reported for the Aihub WordPress theme. Most recent disclosed Aug 6, 2026.

2 critical 2 medium

Running Aihub on your site? Check whether your installed version is affected.

Scan your site free

AI Hub - Startup & Technology WordPress Theme <= 1.3.10 - Authenticated (Subscriber+) Arbitrary File Dowload

medium

The AI Hub - Startup & Technology WordPress Theme theme for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensiti...

CVSS:
6.5
Affected:
up to 1.3.10
Fix:
No patched version reported
Disclosed:
Aug 6, 2026

CVE-2026-65582 on NVD →

LiquidThemes Themes <= Various Versions - Missing Authorization to Authenticated (Subscriber+) All Plugins Deactivated

medium

Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to deactivate all of a site's pl...

CVSS:
4.3
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Aug 27, 2025

CVE-2025-0951 on NVD →

AIHub <= 1.3.7 - Unauthenticated Arbitrary File Upload in generate_image

critical

The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code ex...

CVSS:
9.8
Affected:
up to 1.3.7
Fixed in:
1.3.8
Disclosed:
Apr 18, 2025

CVE-2025-1093 on NVD →

AI Hub [aihub] <= 1.3.3 (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in EPC AI Hub allows Upload a Web Shell to a Web Server. This issue affects AI Hub: from n/a through 1.3.3.

Affected:
up to 1.3.3
Fix:
No patched version reported
Disclosed:
Apr 15, 2025

CVE-2025-26927 on NVD →

AI Hub - Startup & Technology WordPress Theme <= 1.3.7 - Unauthenticated Arbitrary File Upload

critical

The AI Hub plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS:
9.8
Affected:
up to 1.3.7
Fixed in:
1.3.8
Disclosed:
Apr 10, 2025

CVE-2025-26927 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database