
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-63073 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the Dream-Theme "The7" WordPress theme (plugin slug: dt-the7). It affects all versions prior to 12.9.0 (specifically through 12.8.0.2). The vulnerability was reported by João Pedro S Alcântara (Kinorth) on September 5, 2025, and published by Patchstack on October 5, 2025; it was formally registered in NVD on December 9, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically manifesting as a DOM-Based XSS flaw in The7 WordPress theme. DOM-Based XSS occurs when client-side JavaScript reads attacker-controlled data from the DOM (e.g., URL fragments, query parameters) and writes it back to the page without proper sanitization, allowing script injection without server-side involvement. Exploitation requires the attacker to have at least Contributor- or Developer-level privileges on the WordPress site, and a privileged user must interact with a crafted link or page to trigger the payload (Patchstack).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, redirection to malicious sites, or defacement of web content visible to site visitors. The changed scope (S:C) in the CVSS vector indicates the impact can extend beyond the vulnerable component to affect other resources, such as the victim's browser environment (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-63073. The EPSS score is approximately 0.039% (0.000390), indicating a very low probability of exploitation in the near term. Patchstack classifies this as low priority with no impactful threat currently observed. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum Contributor-level access and user interaction, further limiting the attack surface (Patchstack).
<script>, javascript:, onerror=) in URL parameters or fragments directed at pages using The7 theme.The vendor Dream-Theme has released version 12.9.0 of The7 WordPress theme, which patches this vulnerability. Site administrators should update The7 to version 12.9.0 or later immediately. If an immediate update is not possible, consider restricting Contributor and Developer role assignments to trusted users only, and use a WordPress security plugin (such as Patchstack) that provides virtual patching to block exploitation attempts in the interim (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."