Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods DotLife dotlife allows Reflected XSS.This issue affects DotLife: from n/a through < 4.9.5.
Published: 2026-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, allowing a reflected cross‑site scripting (XSS) attack. When a user visits a specially crafted URL or submits a URL-parameter containing JavaScript code, the theme outputs the data without adequate escaping, leading to execution of the attacker’s script in the victim’s browser. This can enable cookie theft, session hijacking, defacement, or other client‑side manipulation.

Affected Systems

WordPress sites that use the ThemeGoods DotLife theme in any version prior to 4.9.5 are affected. The issue spans all releases from the theme’s earliest public version through the last unpatched release specific to these versions.

Risk and Exploitability

The CVSS score of 7.1 indicates medium severity, and the EPSS score of <1% shows that the likelihood of exploitation is low as of the present analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through a reflected user‑controlled input—in particular, an attacker can embed malicious scripts in a query string or other input field that the theme renders without sanitization. No authentication is required, and any site visitor can trigger the exploit by accessing the crafted URL.

Generated by OpenCVE AI on April 28, 2026 at 09:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DotLife theme to version 4.9.5 or later.
  • Apply input validation and output escaping to all user‑supplied parameters used by the theme, ensuring the data cannot be rendered as executable code.
  • If an update is delayed, restrict or block URLs that expose untrusted parameters via a web application firewall or similar access control rule to limit the possibility of reflected XSS.

Generated by OpenCVE AI on April 28, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 29 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods DotLife dotlife allows Reflected XSS.This issue affects DotLife: from n/a through < 4.9.5.
Title WordPress DotLife theme < 4.9.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:00:11.710Z

Reserved: 2025-12-19T10:16:57.339Z

Link: CVE-2025-68520

cve-icon Vulnrichment

Updated: 2026-01-28T15:35:55.364Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:10.763

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-68520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T10:00:06Z

Weaknesses