Vulnerability Details CVE-2021-24270
The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.9%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2021-24270
-
cpe:2.3:a:detheme:dethemekit_for_elementor:-
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.1.2
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.1.2.1
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.1.2.2
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.2.0
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.2.0.1
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.4.0
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.4.2
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.4.3
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.1
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.2.1
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.4
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.4.1
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.4.2
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.4.3
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.4.4
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.5
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.5.1
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.5.2
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.5.3
-
cpe:2.3:a:detheme:dethemekit_for_elementor:1.5.5.4