Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AmentoTech Doctreat doctreat allows Code Injection.This issue affects Doctreat: from n/a through <= 1.6.7.
Published: 2025-10-22
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Doctreat WordPress theme has an inadequate sanitization routine that fails to strip script‑related tags from output. This basic cross‑site scripting flaw (CWE‑80) permits an attacker to inject JavaScript that executes in the browsers of anyone who views the affected content. If an attacker delivers a malicious payload, they could hijack user sessions, steal login credentials, deface the site or redirect visitors to malicious sites. The vulnerability arises from the theme’s outputting of unfiltered content rather than from an underlying platform flaw.

Affected Systems

All installations that use the AmentoTech Doctreat theme version 1.6.7 or earlier are impacted. The issue is confined to the theme itself and does not affect core WordPress, PHP, or the web server environment. Any site that renders theme‑provided content without additional filtering will be vulnerable.

Risk and Exploitability

The CVSS score of 6.3 signals moderate severity, while the EPSS score of less than 1% indicates a low likelihood of large‑scale exploitation at present. The flaw is not included in the CISA KEV catalog. The likely attack vector is content submission via the theme that is subsequently rendered without sanitization; an attacker would craft a post, page, or other theme content containing malicious script, which then runs in visitors’ browsers. Because it is a client‑side flaw, no privileged server access is required to exploit it.

Generated by OpenCVE AI on April 30, 2026 at 14:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Doctreat theme to a version newer than 1.6.7, if an update is available.
  • If an upgrade is not possible, apply WordPress’s built‑in sanitization functions such as wp_kses to all user‑supplied content or install a trusted security plugin that removes disallowed HTML tags.
  • Install a strict Content Security Policy that disallows inline scripts and restricts script sources, thereby limiting the effect of any injected code.

Generated by OpenCVE AI on April 30, 2026 at 14:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 23 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AmentoTech Doctreat doctreat allows Code Injection.This issue affects Doctreat: from n/a through <= 1.6.7.
Title WordPress Doctreat theme <= 1.6.7 - Content Injection vulnerability
Weaknesses CWE-80
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:50.516Z

Reserved: 2025-09-06T04:45:10.579Z

Link: CVE-2025-58970

cve-icon Vulnrichment

Updated: 2025-10-23T13:38:25.081Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:53.207

Modified: 2026-04-27T20:16:23.213

Link: CVE-2025-58970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:00:14Z

Weaknesses