Anona <= 8.0 - Unauthenticated Arbitrary File Deletion
critical
The Anona - Pest Control WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 8.0. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code exe...
- CVSS:
- 9.1
- Affected:
- up to 8.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 13, 2026
CVE-2025-68901 on NVD →
Anona <= 8.0 - Unauthenticated Arbitrary File Download
high
The Anona - Pest Control WordPress Theme theme for WordPress is vulnerable to Path Traversal in all versions up to, and including, 8.0. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 8.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 13, 2026
CVE-2025-68902 on NVD →
Anona <= 8.0 - Authenticated (Subscriber+) PHP Object Injection
high
The Anona theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software....
- CVSS:
- 7.5
- Affected:
- up to 8.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 13, 2026
CVE-2025-68903 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database