Thème WordPress
Vulnérabilités The7 , Website and eCommerce Builder for WordPress
Cette page rassemble les failles publiées pour The7 , Website and eCommerce Builder for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de The7 , Website and eCommerce Builder for WordPress
9 fiches
The7 <= 14.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode 'link' Parameter
The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitization and output escaping on the 'title' component of…
*-14.3.2
14.3.3
14/05/2026
The7 , Ultimate WordPress & WooCommerce Theme <= 12.9.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'the7_fancy_title_css'
The The7 , Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ the7_fancy_title_css’ parameter in all versions up to, and including, 12.9.1 due to insufficient input sanitization and output…
*-12.9.1
12.9.2
24/10/2025
The7 < 12.9.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and excluding, 12.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
[*, 12.9.0)
12.9.0
05/10/2025
The7 < 12.8.1.1 – Authenticated (Contributor+) Local File Inclusion
The The7 theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 12.8.1.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…
[*, 12.8.1.1)
12.8.1.1
04/10/2025
The7 <= 12.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via title and data-dt-img-description Attributes
The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via its lightbox rendering code in all versions up to, and including, 12.6.0 due to insufficient input sanitization and output escaping. The theme’s JavaScript reads user-supplied 'title'…
*-12.6.0
12.7.0
09/08/2025
The7 , Website and eCommerce Builder for WordPress <= 11.13.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via url Attribute
The The7 , Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Icon and Heading widgets in all versions up to, and including, 11.13.0 due…
*-11.13.0
11.14.0
24/06/2024
The7 <= 11.7.3 – Cross-Site Request Forgery
The The7 theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.7.3. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated…
*-11.7.3
11.7.3.1
28/06/2023
The7 <= 11.6.0 – Reflected Cross-Site Scripting
The The7 theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the legacy "DT Flickr" widget in versions up to, and including, 11.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-11.6.0
11.6.1
06/04/2023
The7 , Website and eCommerce Builder for WordPress <= 2.1.0 – Reflected Cross-Site Scripting
The The7 , Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-2.1.0
2.1.1
25/04/2015
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.