Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Detheme

First CVE: May 5, 2021Active for: 5 yearsTotal CVEs: 13
11.6
VTI Score
Low

Detheme develops WordPress plugin products that extend the Elementor page builder, operating within the WordPress ecosystem where plugins present a web-application attack surface centered on input handling and access control. The vendor's vulnerability profile concentrates on cross-site scripting and authorization-bypass weaknesses, which are characteristic of dynamic content-generation platforms where user-supplied data flows into page rendering and permission enforcement. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
5.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Detheme over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2021
5 years ago
Most Recent CVE
Sep 22, 2025
305 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24270MEDIUM
The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors,
May 5, 20215.419NONO
CVE-2024-6283MEDIUM
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of the De Gallery widget in all versions up to and including 2.
Jun 27, 20245.418NONO
CVE-2024-5418MEDIUM
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide widget in all
May 31, 20245.418NONO
CVE-2024-4374MEDIUM
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insuffici
May 18, 20245.418NONO
CVE-2025-57995MEDIUM
Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue
Sep 22, 20254.317NONO
CVE-2025-1526MEDIUM
The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Display Widget (countdown feature) in all versions up to, and incl
Mar 14, 20255.417NONO
CVE-2024-13644MEDIUM
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to
Feb 13, 20255.417NONO
CVE-2024-47632MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor allows Stored XSS.Th
Oct 5, 20245.417NONO
CVE-2025-32260MEDIUM
Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor.This issue affects DethemeKit For Elementor: from n/a through <= 2.1.10.
Apr 10, 20255.316NONO
CVE-2025-26772MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor allows Stored XSS.Th
Feb 17, 20255.416NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
100%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (23.1%)
Unknown0 (0.0%)
Required10 (76.9%)
Privileges Required
Low12 (92.3%)
High0 (0.0%)
None1 (7.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Detheme.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Detheme — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Detheme's Products

View all 3 CNAs →

Top CWEs