Multiple Themes (Various Versions) - Reflected Cross-Site Scripting

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Not available
CVSS Medium (6.1)
Publicly Published February 14, 2022
Last Updated March 11, 2024
Researcher WPScanTeam
Description

Multiple themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'id' parameter found in the '[different-value]_customizer_notify_dismiss_action' and '[different-value]_customizer_notify_dismiss_recommended_plugins' AJAX actions in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The following are additional known variants of the AJAX actions: '[different-value]_customizer_notify_dismiss_recommended_action_callback' & '[different-value]_customizer_notify_dismiss_recommended_plugins_callback'

References

43 affected software package

Software Type Theme
Software Slug travel-booking (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.3
Patched Version
  • 1.2.3
Software Type Theme
Software Slug awpbusinesspress (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 0.2.4
Patched Version
  • 0.2.4
Software Type Theme
Software Slug fifteen (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug rambo (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.1.4
Patched Version
  • 2.1.4
Software Type Theme
Software Slug wallstreet (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.0.5
Patched Version
  • 2.0.5
Software Type Theme
Software Slug rara-business (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.3
Patched Version
  • 1.2.3
Software Type Theme
Software Slug auto-car (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug shopbiz-lite (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.7.7
Patched Version
  • 1.7.7
Software Type Theme
Software Slug cloudpress (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.4.9
Patched Version
  • 2.4.9
Software Type Theme
Software Slug spawp (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.1
Patched Version
  • 1.4.1
Software Type Theme
Software Slug designexo (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.7
Patched Version
  • 3.7
Software Type Theme
Software Slug cactus (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug perfect-portfolio (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.6
Patched Version
  • 1.1.6
Software Type Theme
Software Slug envo-business (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug startkit (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug elitepress (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.0.3
Patched Version
  • 2.0.3
Software Type Theme
Software Slug consultstreet (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.6.7
Patched Version
  • 1.6.7
Software Type Theme
Software Slug spasalon (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.2.1
Patched Version
  • 2.2.1
Software Type Theme
Software Slug colorway (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug arilewp (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.9.7
Patched Version
  • 2.9.7
Software Type Theme
Software Slug businesswp (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1
Patched Version
  • 1.1
Software Type Theme
Software Slug spice-software (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.5
Patched Version
  • 1.1.5
Software Type Theme
Software Slug appointment (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.2.6
Patched Version
  • 3.2.6
Software Type Theme
Software Slug lawyerpress-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.9
Patched Version
Software Type Theme
Software Slug short (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.7.2
Patched Version
  • 1.7.2
Software Type Theme
Software Slug wp-real-estate (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug mediciti-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug quality (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.7.4
Patched Version
  • 2.7.4
Software Type Theme
Software Slug honeypress (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.3.6
Patched Version
  • 2.3.6
Software Type Theme
Software Slug astore (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug blain (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug robolist-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug spiko (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.2
Patched Version
  • 1.1.2
Software Type Theme
Software Slug travel-agency (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.2
Patched Version
  • 1.4.2
Software Type Theme
Software Slug jewelry-store (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.3.5
Patched Version
  • 2.3.5
Software Type Theme
Software Slug ngo-charity-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug busiprof (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.3.8
Patched Version
  • 2.3.8
Software Type Theme
Software Slug hasten-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug busicare (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.9
Patched Version
  • 1.1.9
Software Type Theme
Software Slug eventpress (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 5.6
Patched Version
  • 5.7
Software Type Theme
Software Slug consultera (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Theme
Software Slug businessexpo (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 0.1.4
Patched Version
  • 0.1.4
Software Type Theme
Software Slug ih-business-pro (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.