CVE-2025-68520: WordPress DotLife theme < 4.9.5 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods DotLife dotlife allows Reflected XSS.This issue affects DotLife: from n/a through < 4.9.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68520?
The severity of CVE-2025-68520 is classified as a reflected cross-site scripting (XSS) vulnerability which can lead to data theft or session hijacking.
How do I fix CVE-2025-68520?
To fix CVE-2025-68520, update the ThemeGoods DotLife theme to version 4.9.5 or later.
What versions are affected by CVE-2025-68520?
CVE-2025-68520 affects all versions of the ThemeGoods DotLife theme below 4.9.5.
Can CVE-2025-68520 affect my WordPress site?
Yes, if you are using the affected versions of the ThemeGoods DotLife theme, your WordPress site is vulnerable to CVE-2025-68520.
Is CVE-2025-68520 an easily exploitable vulnerability?
Yes, CVE-2025-68520 is considered easily exploitable as it allows attackers to inject malicious scripts through reflected cross-site scripting.