Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Portfolio Addon designthemes-portfolio-addon allows DOM-Based XSS.This issue affects DesignThemes Portfolio Addon: from n/a through <= 1.5.
Metrics
Affected Vendors & Products
References
History
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Designthemes
Designthemes portfolio Addon Wordpress Wordpress wordpress |
|
| Vendors & Products |
Designthemes
Designthemes portfolio Addon Wordpress Wordpress wordpress |
Tue, 30 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 30 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Portfolio Addon designthemes-portfolio-addon allows DOM-Based XSS.This issue affects DesignThemes Portfolio Addon: from n/a through <= 1.5. | |
| Title | WordPress DesignThemes Portfolio Addon plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: Patchstack
Published: 2025-12-30T10:47:48.297Z
Updated: 2025-12-30T16:03:04.715Z
Reserved: 2025-12-29T11:17:52.921Z
Link: CVE-2025-68977
Updated: 2025-12-30T16:02:57.389Z
Status : Awaiting Analysis
Published: 2025-12-30T11:15:56.260
Modified: 2025-12-31T20:43:05.160
Link: CVE-2025-68977
No data.