Athemes develops WordPress plugins and extensions positioned for site builders and design professionals, with a modestly represented vulnerability footprint concentrated in products like Sydney Toolbox and Athemes Addons for Elementor. The recurring weakness classes affecting the vendor center on web application input handling and PHP file-inclusion flaws, which are characteristic of plugin-based server-side rendering in the WordPress ecosystem. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Athemes over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32158HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for | Apr 10, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-2936MEDIUM The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and including, 1.26 due to insufficient | Mar 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-1447MEDIUM The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aThemes Slider button element in all versions up to, and including, 1.25 due t | Feb 29, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-13547MEDIUM The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 1.0.12 due t | Feb 1, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-51675MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for-elementor-lite all | Nov 9, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-4036MEDIUM The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.30 due to insufficient input sa | May 2, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-3208MEDIUM The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 1.28 due to in | Apr 9, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-22646MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for-elementor-lite all | Mar 27, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-4473MEDIUM The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insuffici | May 14, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Athemes.
Media articles that mention a CVE ID that affects a product developed by Athemes — matched by CVE ID, not by vendor name.