CVE-2025-63073: WordPress The7 theme < 12.9.0 - Cross Site Scripting (XSS) vulnerability
Published Dec 9, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dream-Theme The7 dt-the7 allows DOM-Based XSS.This issue affects The7: from n/a through < 12.9.0.
Affected Software
1 affected component
Dream-Theme The7<12.9.0
Event History
Dec 9, 2025
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-63073?
CVE-2025-63073 is considered a medium severity vulnerability due to its nature of allowing Cross-site Scripting (XSS) attacks.
2
How do I fix CVE-2025-63073?
To fix CVE-2025-63073, ensure that you update Dream-Theme The7 to a version beyond 12.8.0.2.
3
What software is affected by CVE-2025-63073?
CVE-2025-63073 affects Dream-Theme The7 versions from n/a up to and including 12.8.0.2.
4
What is the impact of CVE-2025-63073?
The impact of CVE-2025-63073 is that it allows attackers to execute malicious scripts in the context of a user's browser session.
5
Who is the vendor of the software affected by CVE-2025-63073?
The vendor of the software affected by CVE-2025-63073 is Dream-Theme.