CVE-2023-3708: Multiple DeoThemes Themes <= (Various Versions) - Reflected Cross-Site Scripting
Published Jul 18, 2023
·Updated
Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
5 affected components
DeoThemes Medikaid Wordpress<1.1.3
DeoThemes Amela Wordpress<1.0.14
DeoThemes Arendelle Wordpress<1.1.13
DeoThemes Everse Wordpress<1.8.12
DeoThemes Nokke Wordpress<1.2.4
Event History
Jul 18, 2023
CVE Published
via MITRE·02:01 AM
Data Sourced
via MITRE·02:01 AM
DescriptionSeverityWeakness
Data Sourced
03:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-3708.
2
What is the severity of CVE-2023-3708?
The severity of CVE-2023-3708 is medium.
3
Which software versions are affected by CVE-2023-3708?
The Deothemes Medikaid WordPress theme versions up to and exclusive of 1.1.3 are affected by CVE-2023-3708.
4
What is the CWE ID for CVE-2023-3708?
The CWE ID for CVE-2023-3708 is 79.
5
How can I fix the vulnerability in my Deothemes Medikaid WordPress theme?
To fix the vulnerability in your Deothemes Medikaid WordPress theme, update to a version higher than or equal to 1.1.3.