Detheme develops WordPress plugin products that extend the Elementor page builder, operating within the WordPress ecosystem where plugins present a web-application attack surface centered on input handling and access control. The vendor's vulnerability profile concentrates on cross-site scripting and authorization-bypass weaknesses, which are characteristic of dynamic content-generation platforms where user-supplied data flows into page rendering and permission enforcement. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Detheme over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24270MEDIUM The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, | May 5, 2021 | 5.4 | 19 | NO | NO |
CVE-2024-6283MEDIUM The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of the De Gallery widget in all versions up to and including 2. | Jun 27, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-5418MEDIUM The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide widget in all | May 31, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-4374MEDIUM The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insuffici | May 18, 2024 | 5.4 | 18 | NO | NO |
CVE-2025-57995MEDIUM Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue | Sep 22, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-1526MEDIUM The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Display Widget (countdown feature) in all versions up to, and incl | Mar 14, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-13644MEDIUM The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Gallery widget in all versions up to, and including, 2.1.8 due to | Feb 13, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-47632MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor allows Stored XSS.Th | Oct 5, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-32260MEDIUM Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor.This issue affects DethemeKit For Elementor: from n/a through <= 2.1.10. | Apr 10, 2025 | 5.3 | 16 | NO | NO |
CVE-2025-26772MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor allows Stored XSS.Th | Feb 17, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Detheme.
Media articles that mention a CVE ID that affects a product developed by Detheme — matched by CVE ID, not by vendor name.