theme

Greenmart Vulnerabilities

11 known security issues reported for the Greenmart WordPress theme. Most recent disclosed Dec 30, 2025.

1 critical 1 high 2 medium

Running Greenmart on your site? Check whether your installed version is affected.

Scan your site free

GreenMart [greenmart] <= 4.2.11 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart allows PHP Local File Inclusion.This issue affects Greenmart: from n/a through <= 4.2.11.

Affected:
up to 4.2.11
Fix:
No patched version reported
Disclosed:
Dec 30, 2025

CVE-2025-68983 on NVD →

Greenmart <= 4.2.11 - Authenticated (Contributor+) Local File Inclusion

high

The Greenmart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.11. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...

CVSS:
7.5
Affected:
up to 4.2.11
Fix:
No patched version reported
Disclosed:
Dec 20, 2025

CVE-2025-68983 on NVD →

GreenMart [greenmart] < 4.2.4

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart allows PHP Local File Inclusion. This issue affects Greenmart: from n/a through 4.2.3.

Affected:
up to 4.2.4
Fixed in:
4.2.4
Disclosed:
Jun 27, 2025

CVE-2025-49883 on NVD →

Greenmart <= 4.2.3 - Unauthenticated Local File Inclusion

critical

The Greenmart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.3. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, o...

CVSS:
9.8
Affected:
up to 4.2.3
Fixed in:
4.2.4
Disclosed:
Jun 25, 2025

CVE-2025-49883 on NVD →

Greenmart <= 2.5.1 - Reflected Cross-Site Scripting

medium

The Greenmart theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'callback' parameter in the 'admin-ajax.php' file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

CVSS:
6.1
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
Oct 29, 2020

GreenMart [greenmart] < 2.5.2

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found by ErwanLR (WPScan) in WordPress Greenmart premium theme (versions <= 2.5.1).

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Oct 29, 2020

GreenMart [greenmart] < 2.5.2

unknown

The Greenmart theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'callback' parameter in the 'admin-ajax.php' file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Oct 29, 2020

GreenMart [greenmart] < 2.4.3

unknown

Reflected Cross-Site Scripting (XSS) vulnerability found by Cyber Security Works Pvt. Ltd in WordPress Greenmart premium theme (versions <= 2.4.2).

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Oct 28, 2020

GreenMart [greenmart] < 2.4.3

unknown

[en] The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Oct 27, 2020

CVE-2020-16140 on NVD →

GreenMart – Organic & Food WooCommerce WordPress Theme < 2.4.3 - Reflected Cross-Site Scripting

medium

The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.

CVSS:
6.1
Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Jul 17, 2020

CVE-2020-16140 on NVD →

GreenMart [greenmart] < 2.5.2

unknown

Due to an incomplete fix of CVE-2020-16140 (see https://wpscan.com/vulnerability/10444), the reflected XSS attack is still possible on unauthenticated users, by extracting the search_nonce from the source of the homepage and adding it to the original payload. This is possible because WP nonces are tied to the logged in...

Affected:
up to 2.5.2
Fixed in:
2.5.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database