plugin

Dethemekit For Elementor Vulnerabilities

26 known security issues reported for the Dethemekit For Elementor WordPress plugin. Most recent disclosed Sep 22, 2025.

13 medium

Running Dethemekit For Elementor on your site? Check whether your installed version is affected.

Scan your site free

DethemeKit For Elementor <= 2.1.10 - Missing Authorization

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
5.4
Affected:
up to 2.1.10
Fix:
No patched version reported
Disclosed:
Sep 22, 2025

CVE-2025-57995 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] <= 2.1.10 (unfixed)

unknown

[en] Missing Authorization vulnerability in Detheme DethemeKit For Elementor. This issue affects DethemeKit For Elementor: from n/a through 2.1.10.

Affected:
up to 2.1.10
Fix:
No patched version reported
Disclosed:
Apr 10, 2025

CVE-2025-32260 on NVD →

DethemeKit For Elementor <= 2.1.10 - Missing Authorization

medium

The DethemeKit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.1.10
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2025-32260 on NVD →

DethemeKit for Elementor <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Display Widget (countdown feature) in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributo...

CVSS:
6.4
Affected:
up to 2.1.9
Fixed in:
2.1.10
Disclosed:
Mar 13, 2025

CVE-2025-1526 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit For Elementor allows Stored XSS. This issue affects DethemeKit For Elementor: from n/a through 2.1.8.

Affected:
up to 2.1.9
Fixed in:
2.1.9
Disclosed:
Feb 17, 2025

CVE-2025-26772 on NVD →

DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 2.1.8
Fixed in:
2.1.9
Disclosed:
Feb 14, 2025

CVE-2025-26772 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.9

unknown

[en] The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...

Affected:
up to 2.1.9
Fixed in:
2.1.9
Disclosed:
Feb 13, 2025

CVE-2024-13644 on NVD →

DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via De Gallery Widget

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c...

CVSS:
6.4
Affected:
up to 2.1.8
Fixed in:
2.1.9
Disclosed:
Feb 12, 2025

CVE-2024-13644 on NVD →

DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Protected Post Disclosure

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and ab...

CVSS:
4.3
Affected:
up to 2.1.8
Fixed in:
2.1.9
Disclosed:
Feb 12, 2025

CVE-2025-0661 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.8

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Elementor: from n/a through 2.1.7.

Affected:
up to 2.1.8
Fixed in:
2.1.8
Disclosed:
Oct 5, 2024

CVE-2024-47632 on NVD →

DethemeKit For Elementor <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 2.1.7
Fixed in:
2.1.8
Disclosed:
Sep 30, 2024

CVE-2024-47632 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.6

unknown

[en] The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of the De Gallery widget in all versions up to and including 2.1.5 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated at...

Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Jun 27, 2024

CVE-2024-6283 on NVD →

DethemeKit For Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via URL Parameter of the De Gallery Widget

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of the De Gallery widget in all versions up to and including 2.1.5 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attacke...

CVSS:
5.4
Affected:
up to 2.1.5
Fixed in:
2.1.6
Disclosed:
Jun 26, 2024

CVE-2024-6283 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.5

unknown

[en] The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide widget in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

Affected:
up to 2.1.5
Fixed in:
2.1.5
Disclosed:
May 31, 2024

CVE-2024-5418 on NVD →

DethemeKit For Elementor <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via slitems Attribute

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide widget in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...

CVSS:
6.4
Affected:
up to 2.1.4
Fixed in:
2.1.5
Disclosed:
May 30, 2024

CVE-2024-5418 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.4

unknown

[en] The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...

Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
May 18, 2024

CVE-2024-4374 on NVD →

DethemeKit For Elementor <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor...

CVSS:
6.4
Affected:
up to 2.1.3
Fixed in:
2.1.4
Disclosed:
May 17, 2024

CVE-2024-4374 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.3

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Elementor: from n/a through 2.1.2.

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
May 17, 2024

CVE-2024-34575 on NVD →

DethemeKit For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
May 14, 2024

CVE-2024-34575 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Elementor: from n/a through 2.0.2.

Affected:
up to 2.1.0
Fixed in:
2.1.0
Disclosed:
Apr 17, 2024

CVE-2024-32508 on NVD →

DethemeKit For Elementor <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above,...

CVSS:
6.4
Affected:
up to 2.0.2
Fixed in:
2.1.0
Disclosed:
Apr 15, 2024

CVE-2024-32508 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 1.5.5.5

unknown

[en] The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

Affected:
up to 1.5.5.5
Fixed in:
1.5.5.5
Disclosed:
May 5, 2021

CVE-2021-24270 on NVD →

DethemeKit For Elementor <= 1.5.5.4 - Authenticated Stored Cross-Site Scripting

medium

The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVSS:
5.4
Affected:
up to 1.5.5.5
Fixed in:
1.5.5.5
Disclosed:
Apr 13, 2021

CVE-2021-24270 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 1.5.5.5

unknown

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by WordFence in WordPress DethemeKit For Elementor plugin (versions <= 1.5.5.4).

Affected:
up to 1.5.5.5
Fixed in:
1.5.5.5
Disclosed:
Apr 13, 2021

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.9

unknown
Affected:
up to 2.1.9
Fixed in:
2.1.9

CVE-2025-0661 on NVD →

DethemeKit for Elementor [dethemekit-for-elementor] < 2.1.10

unknown
Affected:
up to 2.1.10
Fixed in:
2.1.10

CVE-2025-1526 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database