CVE-2025-26970: Arktheme The Ark

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Ark Theme Core ark-core allows Code Injection.This issue affects Ark Theme Core: from n/a through < 1.71.0.

Affected products

  • Arktheme The Ark: up to and including 1.70.0

Published 2025-03-03. Last modified 2026-06-17.