xSmart
Jthemes · 4 CVEs
CVE-2025-54002
MEDIUM
WordPress xSmart theme <= 1.2.9.4 - Broken Access Control vulnerability
Jan 22, 2026
CVE-2025-50007
HIGH
WordPress xSmart theme <= 1.2.9.4 - Privilege Escalation vulnerability
Jan 22, 2026
CVE-2025-50006
HIGH
WordPress xSmart theme <= 1.2.9.4 - Reflected Cross Site Scripting (XSS) vulnerability
Jan 22, 2026
CVE-2025-62936
MEDIUM
WordPress xSmart theme <= 1.2.9.4 - Content Injection vulnerability
Oct 27, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-54002 | WordPress xSmart theme <= 1.2.9.4 - Broken Access Control vulnerability | MEDIUM | 0.32% | Jan 22, 2026 |
| CVE-2025-50007 | WordPress xSmart theme <= 1.2.9.4 - Privilege Escalation vulnerability | HIGH | 0.47% | Jan 22, 2026 |
| CVE-2025-50006 | WordPress xSmart theme <= 1.2.9.4 - Reflected Cross Site Scripting (XSS) vulnerability | HIGH | 0.27% | Jan 22, 2026 |
| CVE-2025-62936 | WordPress xSmart theme <= 1.2.9.4 - Content Injection vulnerability | MEDIUM | 0.26% | Oct 27, 2025 |
Showing 1 to 4 of 4 CVEs