← Back

CVE-2023-3708

nvd nist
Published: Jul 18, 2023Modified: Apr 8, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: security@wordfence.com (Secondary)

Description

Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Affected (5)

5 products
Amela
Arendelle
Everse
Medikaid
Nokke
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.14
Before 1.1.13
Before 1.8.12
Before 1.1.3
Before 1.2.4

References (12)

Source: security@wordfence.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes

Timeline

No history available yet.