Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amela Theme | — | Update amela theme to version 1.0.14, or a newer patched version | Dec 8, 2025 | Jul 17, 2023 |
| Arendelle Theme | — | Update arendelle theme to version 1.1.13, or a newer patched version | Dec 8, 2025 | Jul 17, 2023 |
| Everse Theme | — | Update everse theme to version 1.8.12, or a newer patched version | Dec 8, 2025 | Jul 17, 2023 |
| Medikaid Theme | — | Update medikaid theme to version 1.1.3, or a newer patched version | Dec 8, 2025 | Jul 17, 2023 |
| Nokke Theme | — | Update nokke theme to version 1.2.4, or a newer patched version | Dec 8, 2025 | Jul 17, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub