theme

Anona Vulnerabilities

3 known security issues reported for the Anona WordPress theme. Most recent disclosed Jan 13, 2026.

1 critical 2 high

Running Anona on your site? Check whether your installed version is affected.

Scan your site free

Anona <= 8.0 - Unauthenticated Arbitrary File Deletion

critical

The Anona - Pest Control WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 8.0. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code exe...

CVSS:
9.1
Affected:
up to 8.0
Fix:
No patched version reported
Disclosed:
Jan 13, 2026

CVE-2025-68901 on NVD →

Anona <= 8.0 - Unauthenticated Arbitrary File Download

high

The Anona - Pest Control WordPress Theme theme for WordPress is vulnerable to Path Traversal in all versions up to, and including, 8.0. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 8.0
Fix:
No patched version reported
Disclosed:
Jan 13, 2026

CVE-2025-68902 on NVD →

Anona <= 8.0 - Authenticated (Subscriber+) PHP Object Injection

high

The Anona theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software....

CVSS:
7.5
Affected:
up to 8.0
Fix:
No patched version reported
Disclosed:
Jan 13, 2026

CVE-2025-68903 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database