CVE-2023-3708: Deothemes Amela

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Affected products

  • Deothemes Amela: before 1.0.14 (fixed in 1.0.14)
  • Deothemes Arendelle: before 1.1.13 (fixed in 1.1.13)
  • Deothemes Everse: before 1.8.12 (fixed in 1.8.12)
  • Deothemes Medikaid: before 1.1.3 (fixed in 1.1.3)
  • Deothemes Nokke: before 1.2.4 (fixed in 1.2.4)

Published 2023-07-18. Last modified 2026-06-17.