https://www.wpvulnerability.net/theme/dt-the7/

{“error”:0,”message”:null,”data”:{“name”:”The7″,”theme”:”dt-the7″,”link”:null,”latest”:null,”closed”:null,”vulnerability”:[{“uuid”:”4e90b746721624be4a3ff5fffee5efc1b2bd5588069f06b977475b567cebc6a0″,”name”:”The7 [dt-the7] < 2.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7be6b51ba97a25a83c20d91d5cf309bd5d07ca33","name":"The7 \u2014 Website and eCommerce Builder for WordPress <= 2.1.0 – Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/dt-the7\/the7-website-and-ecommerce-builder-for-wordpress-210-reflected-cross-site-scripting","description":"The The7 \u2014 Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2015-04-25"}],"impact":[]},{"uuid":"1e077fcbbebdbe78638398b4fd218b179574f39341f71f965b5a66b3461c6ace","name":"The7 [dt-the7] < 11.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"11.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-29100","name":"CVE-2023-29100","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-29100","description":"[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dream-Theme The7 plugin <=\u00a011.6.0 versions.","date":"2023-06-23"},{"id":"c451fc62329af8d400b2d791e8b3b63a85ce4320","name":"WordPress The7 Theme <= 11.6.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/dt-the7\/vulnerability\/wordpress-the7-theme-11-6-0-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress The7 theme to the latest available version (at least 11.6.1).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress The7 Theme. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 11.6.1.","date":"2023-04-06"},{"id":"ffaadad8c1e5b2fe7c1770614d77ff0285030979","name":"The7 <= 11.6.0 – Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/dt-the7\/the7-1160-reflected-cross-site-scripting","description":"The The7 theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the legacy \"DT Flickr\" widget in versions up to, and including, 11.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-04-06"},{"id":"ef0b0bd5-b2a7-423b-9c49-40bba4c200d3","name":"The7 < 11.6.1 – Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/ef0b0bd5-b2a7-423b-9c49-40bba4c200d3","description":"The plugin does not sanitise and escape a parameter from the legacy DT Flickr widget before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"dbad648c12d789c3f5b7fb766461a796008c259d960af28fb2ac8903c9efeb47","name":"The7 [dt-the7] <= 11.6.0 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"11.6.0","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2023-32123","name":"CVE-2023-32123","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-32123","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Dream-Theme The7 allows Stored XSS.This issue affects The7: from n\/a through 11.7.3.","date":"2023-11-13"},{"id":"6f6d938abae4331749a81638d65be9c2b34fb3b0","name":"WordPress The7 Theme <= 11.6.0 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/dt-the7\/vulnerability\/wordpress-the7-website-and-ecommerce-builder-for-wordpress-theme-11-0-3-cross-site-request-forgery-csrf","description":"No patched version is provided by the vendor.\nDave Jong (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress The7 Theme. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has not been known to be fixed yet.","date":"2023-06-27"},{"id":"baaf4fdd221b678c338c4a39ecd0ffa7e192cd6d","name":"The7 <= 11.7.3 – Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/dt-the7\/the7-1160-cross-site-request-forgery","description":"The The7 theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.7.3. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-06-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"91724eb75443e5fbcd2b6bd6cfebbebc21baba1e09fa97ad70f576c970258ac2","name":"The7 [dt-the7] < 2.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6e5c3f01-3421-4a9d-a7fd-9b660f164f0b","name":"The7 Premium Theme < 2.1.1 – Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/6e5c3f01-3421-4a9d-a7fd-9b660f164f0b","description":"The the7 WordPress theme was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"ac818b1e9b8ed1f83bee6a393088596d789c66537cbcd7e786611c53ce4b5284","name":"The7 [dt-the7] < 11.14.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"11.14.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5451","name":"CVE-2024-5451","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5451","description":"[en] The The7 \u2014 Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Icon and Heading widgets in all versions up to, and including, 11.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-25"},{"id":"9b1173cfd92529430b505038495d001869face6d","name":"The7 \u2014 Website and eCommerce Builder for WordPress <= 11.13.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via url Attribute","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/dt-the7\/the7-website-and-ecommerce-builder-for-wordpress-11130-authenticated-contributor-stored-cross-site-scripting-via-url-attribute","description":"The The7 \u2014 Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Icon and Heading widgets in all versions up to, and including, 11.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-24"},{"id":"64269a8617b614cfbf43946226209891b5b5372b","name":"WordPress The7 Theme <= 11.13.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/dt-the7\/vulnerability\/wordpress-the7-theme-11-13-0-authenticated-contributor-stored-cross-site-scripting-via-url-attribute-vulnerability","description":"

WordPress The7 Theme <= 11.13.0 is vulnerable to Cross Site Scripting (XSS)

Affected Version <= 11.13.0

Fixed in version 11.14.0 “,”date”:”2024-06-25″}],”impact”:{“cvss”:{“version”:”3.1″,”vector”:”CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N”,”av”:”n”,”ac”:”l”,”pr”:”l”,”ui”:”n”,”s”:”c”,”c”:”l”,”i”:”l”,”a”:”n”,”score”:”6.4″,”severity”:”m”,”exploitable”:”0.0″,”impact”:”0.0″},”cwe”:[{“cwe”:”CWE-79″,”name”:”Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)”,”description”:”The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.”}]}},{“uuid”:”7a5dd97fdc6183cd742645df3c793264139744fb24f5dded3ace9e6017d56492″,”name”:”The7 [dt-the7] < 12.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"12.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-7726","name":"CVE-2025-7726","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-7726","description":"","date":null},{"id":"6321781024be98bf5c0ce42f076177c669d05182","name":"The7 <= 12.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via title and data-dt-img-description Attributes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/dt-the7\/the7-1260-authenticated-contributor-stored-cross-site-scripting-via-title-and-data-dt-img-description-attributes","description":"The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via its lightbox rendering code in all versions up to, and including, 12.6.0 due to insufficient input sanitization and output escaping. The theme’s JavaScript reads user-supplied 'title' and 'data-dt-img-description' attributes directly via jQuery.attr(), concatenates them into an HTML string, and inserts that string into the DOM using methods such as jQuery.html() without escaping or filtering. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null},{"id":"d8d2a5b184016515c50baa85989d54dc350a509f","name":"WordPress The7 Theme <= 12.6.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/dt-the7\/vulnerability\/wordpress-the7-plugin-12-6-0-authenticated-contributor-stored-cross-site-scripting-via-title-and-data-dt-img-description-attributes-vulnerability","description":"

WordPress The7 Theme <= 12.6.0 is vulnerable to Cross Site Scripting (XSS)

Software: The7

Fixed in version 12.7.0

Affected Version <= 12.6.0

CVE: CVE-2025-7726″,”date”:”2025-08-11″}],”impact”:[]},{“uuid”:”408426e7497abeacf4f3fe33042f76d3942711aeb803ad888972117b629a803e”,”name”:”The7 [dt-the7] < 12.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"12.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-11897","name":"CVE-2025-11897","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-11897","description":"[en] The The7 \u2014 Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018 the7_fancy_title_css\u2019 parameter in all versions up to, and including, 12.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-10-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d9b7b04b89a98c5b46e90ecfca6216d6fadebf04a4ac25558552ee9c30dacd18","name":"The7 [dt-the7] <= 12.8.0.2 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"12.8.0.2","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2025-63074","name":"CVE-2025-63074","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-63074","description":"[en] Improper Control of Filename for Include\/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 dt-the7 allows PHP Local File Inclusion.This issue affects The7: from n\/a through <= 12.8.0.2.","date":"2025-12-09"}],"impact":[]},{"uuid":"0a134ee85db84adafb8a0ccf92e9b335468fea23a2f45a72545018149333cca9","name":"The7 [dt-the7] <= 12.8.0.2 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"12.8.0.2","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2025-63073","name":"CVE-2025-63073","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-63073","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dream-Theme The7 dt-the7 allows DOM-Based XSS.This issue affects The7: from n\/a through <= 12.8.0.2.","date":"2025-12-09"}],"impact":[]}]},"updated":"1765356837"}