Junglewise Threat Intelligence

CVE-2025-52747: Jthemes Themebox Reflected XSS in Digital Products Ecommerce theme

CVE-2025-52747 · Severity: high · CVSS 7.1 · Published 2026-05-27

Executive brief

The Themebox ecommerce theme for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs when a user clicks on a specially crafted link, potentially leading to unauthorized actions being performed in the user's browser, such as data theft or redirection to malicious sites. As of the latest report, there is no official patch available from the developer.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Jthemes Themebox - Digital Products Ecommerce theme for WordPress (versions <= 1.4.2) due to improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions if the victim is an authenticated administrator. No official patch has been released by the vendor at the time of this advisory.

Affected products

  • Jthemes Themebox - Digital Products Ecommerce <= 1.4.2

Timeline

  • 2025-07-11: other: Vulnerability reported by Tran Nguyen Bao Khanh
  • 2025-08-10: advisory: Initial Patchstack advisory published
  • 2026-05-27: disclosed: CVE published to NVD dataset

References