WordPress DeepDigital Theme Content Injection Vulnerability

Vulnerability

A content injection vulnerability has been identified in the WordPress DeepDigital theme, specifically in versions through 1.0.2. This vulnerability allows for improper neutralization of script-related HTML tags, leading to basic cross-site scripting (XSS) issues. Additionally, it enables arbitrary execution of shortcodes, which could be exploited to inject malicious content or phishing pages into the site's posts and pages.

Impact

Exploitation of this vulnerability could result in unauthorized content being injected into WordPress pages or posts, potentially including malicious or phishing-related material.

Added: Jan 22, 2026, 7:33 PM
Updated: Jan 22, 2026, 7:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.6
remediation
0.0
relevance
2.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.