(#Several vulnerabilities have been identified in the following Wordpress themes:#- Goodnews: cross-site scripting#- Authentic: arbitrary file download#- Epic: arbitrary file download#- Antioch: arbitrary file download#- ProjectTheme: multiple cross-site scripting#- ProjectTheme: cross-site request forgery#- ProjectTheme: user ID disclosure when sending a private message#- Beauty Clean: arbitrary file upload.##Proofs of concept are available.)