theme

Dt Chocolate Vulnerabilities

20 known security issues reported for the Dt Chocolate WordPress theme. Most recent disclosed Aug 1, 2014.

2 critical 1 high 4 medium

Running Dt Chocolate on your site? Check whether your installed version is affected.

Scan your site free

Chocolate [dt-chocolate] < 1.1

unknown

This theme is prone to an image open redirect vulnerability. Update the theme.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Chocolate [dt-chocolate] < 1.1

unknown

This WordPress theme is prone to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary script or HTML. Update the theme.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

DT Chocolate (All Versions) - Cross-Site Scripting

medium

The DT Chocolate theme plugin for WordPress is vulnerable to Cross-Site Scripting in all versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Jan 13, 2014

Chocolate [dt-chocolate] < 100 (unfixed + closed)

unknown

The DT Chocolate theme plugin for WordPress is vulnerable to Cross-Site Scripting in all versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Jan 13, 2014

DT Chocolate <= 1.0 - Open Redirect

medium

The DT Chocolate theme for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.0. This is due to a lack of sanitization of user-supplied input via the 'image' parameter. This makes it possible for attackers to redirect users to arbitrary websites.

CVSS:
4.7
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 3, 2013

Chocolate [dt-chocolate] <= 1.0 (unfixed)

unknown

The DT Chocolate theme for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.0. This is due to a lack of sanitization of user-supplied input via the 'image' parameter. This makes it possible for attackers to redirect users to arbitrary websites.

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Feb 3, 2013

Chocolate WP – Responsive Photography Theme (All Versions) - Arbitrary File Upload

critical

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to arbitrary file uploads due to inclusion of a vulnerable version of TimThumb in all versions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution pos...

CVSS:
9.8
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate WP – Responsive Photography Theme (All Versions) - Remote File Inclusion

critical

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Remote File Inclusion in all versions due to inclusion of a vulnerable version of TimThumb. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.

CVSS:
9.8
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate WP – Responsive Photography Theme (All Versions) - Denial of Service and Abuse of Functionality

high

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Denial of Service and Abuse of Functionality in all versions. This is due to inclusion of a vulnerable version of TimThumb. This makes it possible for unauthenticated attackers to send users to other websites if they can successfully trick a...

CVSS:
7.5
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate WP – Responsive Photography Theme (All Versions) - Cross-Site Scripting

medium

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable version of TimThumb in all versions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

CVSS:
6.1
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate WP – Responsive Photography Theme (All Versions) - Full Path Disclosure

medium

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Sensitive Data Exposure in all versions via the index.php file and inclusion of a vulnerable version of TimThumb. This can allow unauthenticated attackers to extract sensitive data including the full path of the WordPress installation.

CVSS:
5.3
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate [dt-chocolate] <= 3.0 (unfixed + closed)

unknown

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable version of TimThumb in all versions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...

Affected:
up to 3.0
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate [dt-chocolate] < 100 (unfixed + closed)

unknown

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Remote File Inclusion in all versions due to inclusion of a vulnerable version of TimThumb. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate [dt-chocolate] < 100 (unfixed + closed)

unknown

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Denial of Service and Abuse of Functionality in all versions. This is due to inclusion of a vulnerable version of TimThumb. This makes it possible for unauthenticated attackers to send users to other websites if they can successfully trick a...

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate [dt-chocolate] < 100 (unfixed + closed)

unknown

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to arbitrary file uploads due to inclusion of a vulnerable version of TimThumb in all versions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution pos...

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate [dt-chocolate] <= 3.0 (unfixed + closed)

unknown

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Sensitive Data Exposure in all versions via the index.php file and inclusion of a vulnerable version of TimThumb. This can allow unauthenticated attackers to extract sensitive data including the full path of the WordPress installation.

Affected:
up to 3.0
Fix:
No patched version reported
Disclosed:
Jan 24, 2013

Chocolate [dt-chocolate] < 1.1 (closed)

unknown

The Chocolate Theme is prone to multiple security vulnerabilities. These vulnerabilities allow an attacker to cause denial-of-service conditions, execute arbitrary script code in the browser of an user in the context of the affected site or upload arbitrary files. Other attacks are also possible. Update the theme.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jan 23, 2013

Chocolate [dt-chocolate] < 100 (unfixed)

unknown

The dt-chocolate WordPress theme was affected by security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Chocolate [dt-chocolate] < 100 (unfixed)

unknown

The dt-chocolate WordPress theme was affected by a jPlayer XSS security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Chocolate [dt-chocolate] < 100 (unfixed)

unknown

The dt-chocolate WordPress theme was affected by an Image Open redirect security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database