All 3 CVE vulnerabilities found in DesignThemes Core Features, with AI-generated Chinese analysis, references, and POCs.
Vendor: designthemes
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-69302 | WordPress DesignThemes Core Features plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 | 6.1AI | MediumAI | 2026-02-20 |
| CVE-2025-0845 | DesignThemes Core Features <= 4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 | 6.4 | Medium | 2025-03-25 |
| CVE-2024-13471 | DesignThemes Core Features <= 4.7 - Missing Authorization to Unauthenticated Arbitrary File Read via dt_process_imported_file CWE-22 | 7.5 | High | 2025-03-05 |
All 3 known CVE vulnerabilities affecting DesignThemes Core Features with full Chinese analysis, references, and POCs where available.