Theme Vulnerability Hub
Theme 7 known issues Latest disclosed Jan 13, 2014

Chocolate WP – Responsive Photography Theme | Photography Vulnerabilities

Review known vulnerability records for the WordPress theme Chocolate WP – Responsive Photography Theme | Photography (`dt-chocolate`), including severity, CVE references, affected versions, and patch status.

Known Records
7
High or Critical
3
Patch Coverage
100%
Last Updated
Aug 15, 2024
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Chocolate WP – Responsive Photography Theme | Photography so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
7 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
2 critical and 1 high severity finding.
Recent CVEs
This page still provides patch and version coverage even when a CVE ID is not listed.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Medium No patch listed

DT Chocolate <= 1.0 - Open Redirect

The DT Chocolate theme for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.0. This is due to a lack of sanitization of user-supplied input via the 'image' parame...

Published
Feb 03, 2013
Patch Status
Not published
Known Vulnerabilities

Reports for Chocolate WP – Responsive Photography Theme | Photography

Sorted by latest disclosure date so newly published issues surface first.

Theme Medium Patched: No
DT Chocolate (All Versions) - Cross-Site Scripting

The DT Chocolate theme plugin for WordPress is vulnerable to Cross-Site Scripting in all versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Published
Jan 13, 2014
Patched Release
Not published
Affected Versions
*
Next Step
Open the full report for remediation notes and references.
Theme Medium Patched: No
DT Chocolate <= 1.0 - Open Redirect

The DT Chocolate theme for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.0. This is due to a lack of sanitization of user-supplied input via the 'image' parameter. This makes it possible for attackers to redirect users to arbitrary websites.

Published
Feb 03, 2013
Patched Release
Not published
Affected Versions
Versions up to 1.0
Next Step
Open the full report for remediation notes and references.
Theme High Patched: No
Chocolate WP – Responsive Photography Theme (All Versions) - Denial of Service and Abuse of Functionality

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Denial of Service and Abuse of Functionality in all versions. This is due to inclusion of a vulnerable version of TimThumb. This makes it possible for unauthenticated attackers to send users to other w...

Published
Jan 24, 2013
Patched Release
Not published
Affected Versions
*
Next Step
Open the full report for remediation notes and references.
Theme Critical Patched: No
Chocolate WP – Responsive Photography Theme (All Versions) - Remote File Inclusion

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Remote File Inclusion in all versions due to inclusion of a vulnerable version of TimThumb. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.

Published
Jan 24, 2013
Patched Release
Not published
Affected Versions
*
Next Step
Open the full report for remediation notes and references.
Theme Medium Patched: No
Chocolate WP – Responsive Photography Theme (All Versions) - Cross-Site Scripting

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to inclusion of a vulnerable version of TimThumb in all versions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

Published
Jan 24, 2013
Patched Release
Not published
Affected Versions
*
Next Step
Open the full report for remediation notes and references.
Theme Critical Patched: No
Chocolate WP – Responsive Photography Theme (All Versions) - Arbitrary File Upload

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to arbitrary file uploads due to inclusion of a vulnerable version of TimThumb in all versions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server...

Published
Jan 24, 2013
Patched Release
Not published
Affected Versions
*
Next Step
Open the full report for remediation notes and references.
Theme Medium Patched: No
Chocolate WP – Responsive Photography Theme (All Versions) - Full Path Disclosure

The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Sensitive Data Exposure in all versions via the index.php file and inclusion of a vulnerable version of TimThumb. This can allow unauthenticated attackers to extract sensitive data including the full p...

Published
Jan 24, 2013
Patched Release
Not published
Affected Versions
*
Next Step
Open the full report for remediation notes and references.