We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings which includes custom JavaScript that is enabled site-wide. This issue was escalated to Envato over two months from the date of this disclosure and the issue is still vulnerable.
Reserved 2025-01-15 | Published 2025-05-02 | Updated 2025-05-02 | Assigner Wordfence2025-05-01: | Disclosed |
Lucio Sá
www.wordfence.com/...-a73a-46f4-853e-116792d612f5?source=cve
themeforest.net/...eyot-wordpress-real-estate-theme/19514964
Support options