Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

DethemeKit For Elementor — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in DethemeKit For Elementor, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the DethemeKit For Elementor plugin developed by the vendor DethemeKit, categorized under web application weaknesses. It aggregates reports of diverse security flaws, including cross-site scripting, privilege escalation, and insecure direct object references, covering findings reported from early 2021 through the present date. By consulting this resource, researchers and administrators can track vendor advisories related to this specific ecosystem, gain a deeper understanding of the mechanics behind common weakness classes in Elementor-based extensions, and look up the product's historical vulnerability profile to assess risk exposure over time. The collection aims to provide a centralized view of the security landscape surrounding DethemeKit For Elementor, enabling better informed decisions regarding patch management and plugin selection. It serves as a reference for security professionals seeking to monitor the remediation pace of known issues or to identify patterns in how the vendor responds to disclosed flaws. The data reflects publicly available information and does not imply the existence of unreported vulnerabilities. Users are encouraged to verify specific findings against official vendor channels for the most accurate and current mitigation strategies. This overview highlights the importance of maintaining up-to-date installations to protect against established threats in the WordPress plugin directory.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2025-57995 WordPress DethemeKit For Elementor Plugin <= 2.1.10 - Broken Access Control Vulnerability CWE-862 4.3 Medium 2025-09-22
CVE-2025-32260 WordPress DethemeKit For Elementor plugin <= 2.1.10 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-04-10
CVE-2025-1526 DethemeKit for Elementor <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2025-03-14
CVE-2025-26772 WordPress DethemeKit For Elementor plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-02-17
CVE-2025-0661 DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Protected Post Disclosure CWE-639 4.3 Medium 2025-02-13
CVE-2024-13644 DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via De Gallery Widget CWE-79 6.4 Medium 2025-02-13
CVE-2024-47632 WordPress DethemeKit For Elementor plugin <= 2.1.7 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-10-05
CVE-2024-6283 DethemeKit For Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via URL Parameter of the De Gallery Widget CWE-79 5.4 Medium 2024-06-27
CVE-2024-5418 DethemeKit For Elementor <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via slitems Attribute CWE-79 6.4 Medium 2024-05-31
CVE-2024-4374 DethemeKit For Elementor <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets CWE-79 6.4 Medium 2024-05-18
CVE-2024-34575 WordPress DethemeKit For Elementor plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-05-17
CVE-2024-32508 WordPress DethemeKit For Elementor plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-04-17
CVE-2021-24270 DethemeKit For Elementor < 1.5.5.5 - Contributor+ Stored XSS CWE-79 5.4 - 2021-05-05

All 13 known CVE vulnerabilities affecting DethemeKit For Elementor with full Chinese analysis, references, and POCs where available.