Cross-Site Scripting
10 records76.9%First: 2021. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 13 vulnerability records associated with DethemeKit for Elementor, published between 2021 and 2025.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2021 | 1 | |
| 2024 | 6 | |
| 2025 | 6 |
| Severity | Records | Share |
|---|---|---|
| Medium | 13 | 100% |
First: 2021. Latest: 2025.
First: 2025. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.1.102.1.92.1.82.1.62.1.52.1.42.1.32.1.01.5.5.5Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.1.10 | DethemeKit For Elementor <= 2.1.10 - Missing Authorization | September 22, 2025 | Not supplied | Medium |
*-2.1.10 | DethemeKit For Elementor <= 2.1.10 - Missing Authorization | April 4, 2025 | Not supplied | Medium |
*-2.1.9 | DethemeKit for Elementor <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting | March 13, 2025 | 2.1.10 | Medium |
*-2.1.8 | DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting | February 14, 2025 | 2.1.9 | Medium |
*-2.1.8 | DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via De Gallery Widget | February 12, 2025 | 2.1.9 | Medium |
*-2.1.8 | DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Protected Post Disclosure | February 12, 2025 | 2.1.9 | Medium |
*-2.1.7 | DethemeKit For Elementor <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | September 30, 2024 | 2.1.8 | Medium |
*-2.1.5 | DethemeKit For Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via URL Parameter of the De Gallery Widget | June 26, 2024 | 2.1.6 | Medium |
*-2.1.4 | DethemeKit For Elementor <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via slitems Attribute | May 30, 2024 | 2.1.5 | Medium |
*-2.1.3 | DethemeKit For Elementor <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | May 17, 2024 | 2.1.4 | Medium |
*-2.1.2 | DethemeKit For Elementor <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | May 14, 2024 | 2.1.3 | Medium |
*-2.0.2 | DethemeKit For Elementor <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | April 15, 2024 | 2.1.0 | Medium |
[*, 1.5.5.5) | DethemeKit For Elementor <= 1.5.5.4 - Authenticated Stored Cross-Site Scripting | April 13, 2021 | 1.5.5.5 | Medium |
Selected source records
Published: September 22, 2025
Published: April 4, 2025
Published: March 13, 2025
Published: February 14, 2025
Published: February 12, 2025
Published: February 12, 2025
Published: September 30, 2024
Published: June 26, 2024
Published: May 14, 2024
Published: May 30, 2024
Published: April 15, 2024
Published: February 14, 2025
Published: February 12, 2025
Published: March 13, 2025
Published: September 30, 2024
Published: May 17, 2024
Published: September 22, 2025
Published: April 4, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.