Junglewise Threat Intelligence

CVE-2026-6646: Dream-Theme The7 Stored XSS in dt_default_button shortcode

CVE-2026-6646 · Severity: medium · CVSS 6.4 · Published 2026-05-15

Executive brief

The7, a popular multi-purpose WordPress theme, contains a security vulnerability that allows users with basic contributor-level access to inject malicious scripts into website pages. This occurs through a specific button component used to build page layouts. If exploited, these scripts will run automatically in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'title' component of the 'link' shortcode parameter within the 'dt_default_button' shortcode. An authenticated attacker with Contributor-level access or higher can exploit this by embedding malicious JavaScript into a page's content. Because the theme fails to properly neutralize this input before it is rendered, the script is stored on the server and executed in the context of any user's browser who navigates to the affected page. This vulnerability is addressed in version 14.3.3.

Affected products

  • Dream-Theme The7 Theme Up to and including 14.3.2

Timeline

  • 2026-05-08: patched: Fixed in version 14.3.3
  • 2026-05-15: disclosed: CVE published and NVD record created

References