DethemeKit For Elementor <= 2.1.10 - Missing Authorization
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 5.4
- Affected:
- up to 2.1.10
- Fix:
- No patched version reported
- Disclosed:
- Sep 22, 2025
CVE-2025-57995 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] <= 2.1.10 (unfixed)
unknown
[en] Missing Authorization vulnerability in Detheme DethemeKit For Elementor. This issue affects DethemeKit For Elementor: from n/a through 2.1.10.
- Affected:
- up to 2.1.10
- Fix:
- No patched version reported
- Disclosed:
- Apr 10, 2025
CVE-2025-32260 on NVD →
DethemeKit For Elementor <= 2.1.10 - Missing Authorization
medium
The DethemeKit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.1.10
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2025-32260 on NVD →
DethemeKit for Elementor <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Display Widget (countdown feature) in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributo...
- CVSS:
- 6.4
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.10
- Disclosed:
- Mar 13, 2025
CVE-2025-1526 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit For Elementor allows Stored XSS. This issue affects DethemeKit For Elementor: from n/a through 2.1.8.
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.9
- Disclosed:
- Feb 17, 2025
CVE-2025-26772 on NVD →
DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.9
- Disclosed:
- Feb 14, 2025
CVE-2025-26772 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.9
unknown
[en] The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.9
- Disclosed:
- Feb 13, 2025
CVE-2024-13644 on NVD →
DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via De Gallery Widget
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...
- CVSS:
- 6.4
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.9
- Disclosed:
- Feb 12, 2025
CVE-2024-13644 on NVD →
DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Protected Post Disclosure
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and ab...
- CVSS:
- 4.3
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.9
- Disclosed:
- Feb 12, 2025
CVE-2025-0661 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.8
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Elementor: from n/a through 2.1.7.
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.8
- Disclosed:
- Oct 5, 2024
CVE-2024-47632 on NVD →
DethemeKit For Elementor <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.8
- Disclosed:
- Sep 30, 2024
CVE-2024-47632 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.6
unknown
[en] The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of the De Gallery widget in all versions up to and including 2.1.5 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated at...
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.6
- Disclosed:
- Jun 27, 2024
CVE-2024-6283 on NVD →
DethemeKit For Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via URL Parameter of the De Gallery Widget
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of the De Gallery widget in all versions up to and including 2.1.5 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attacke...
- CVSS:
- 5.4
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.6
- Disclosed:
- Jun 26, 2024
CVE-2024-6283 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.5
unknown
[en] The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide widget in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.5
- Disclosed:
- May 31, 2024
CVE-2024-5418 on NVD →
DethemeKit For Elementor <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via slitems Attribute
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide widget in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...
- CVSS:
- 6.4
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.5
- Disclosed:
- May 30, 2024
CVE-2024-5418 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.4
unknown
[en] The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- May 18, 2024
CVE-2024-4374 on NVD →
DethemeKit For Elementor <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor...
- CVSS:
- 6.4
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.4
- Disclosed:
- May 17, 2024
CVE-2024-4374 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.3
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Elementor: from n/a through 2.1.2.
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- May 17, 2024
CVE-2024-34575 on NVD →
DethemeKit For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- May 14, 2024
CVE-2024-34575 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Elementor: from n/a through 2.0.2.
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.0
- Disclosed:
- Apr 17, 2024
CVE-2024-32508 on NVD →
DethemeKit For Elementor <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above,...
- CVSS:
- 6.4
- Affected:
- up to 2.0.2
- Fixed in:
- 2.1.0
- Disclosed:
- Apr 15, 2024
CVE-2024-32508 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 1.5.5.5
unknown
[en] The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- Affected:
- up to 1.5.5.5
- Fixed in:
- 1.5.5.5
- Disclosed:
- May 5, 2021
CVE-2021-24270 on NVD →
DethemeKit For Elementor <= 1.5.5.4 - Authenticated Stored Cross-Site Scripting
medium
The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
- CVSS:
- 5.4
- Affected:
- up to 1.5.5.5
- Fixed in:
- 1.5.5.5
- Disclosed:
- Apr 13, 2021
CVE-2021-24270 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 1.5.5.5
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress DethemeKit For Elementor plugin (versions <= 1.5.5.4).
- Affected:
- up to 1.5.5.5
- Fixed in:
- 1.5.5.5
- Disclosed:
- Apr 13, 2021
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.9
unknown
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.9
CVE-2025-0661 on NVD →
DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.10
unknown
- Affected:
- up to 2.1.10
- Fixed in:
- 2.1.10
CVE-2025-1526 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database