CVE-2025-68978: WordPress DesignThemes Core plugin <= 1.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Core designthemes-core allows DOM-Based XSS.This issue affects DesignThemes Core: from n/a through <= 1.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68978?
The severity of CVE-2025-68978 is classified as a moderate risk due to the potential for DOM-based cross-site scripting (XSS).
How do I fix CVE-2025-68978?
To fix CVE-2025-68978, upgrade the DesignThemes Core plugin to version 1.7 or higher, which addresses the XSS vulnerability.
Which versions are affected by CVE-2025-68978?
CVE-2025-68978 affects versions of DesignThemes Core up to and including 1.6.
What type of vulnerability is CVE-2025-68978?
CVE-2025-68978 is a cross-site scripting (XSS) vulnerability that arises from improper handling of input during web page generation.
Who is the vendor for the product associated with CVE-2025-68978?
The vendor for the product associated with CVE-2025-68978 is DesignThemes.