{"error":0,"message":null,"data":{"name":"Salient","theme":"salient","link":"https:\/\/themeforest.net\/item\/salient-responsive-multipurpose-theme\/4363266","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"16486f7dd5ec0583dc6869d3fd7e8796445c1d715b3a245f2f18e65c0f07e180","name":"Salient [salient] < 5.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1c12869a67775f21ef25c2395854d696d5d18cd8","name":"WordPress Salient Theme <= 4.9 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/salient\/vulnerability\/wordpress-salient-theme-4-9-cross-site-scripting","description":"This vulnerability allows an attacker to inject arbitrary web script or HTML.\nUpdate the theme.","date":"2015-06-16"}],"impact":[]},{"uuid":"f49d0a07ed5aea862098b91bcbe5206e93d576cb0ad70377992995c9a6875247","name":"Salient [salient] < 5.5.53","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.5.53","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9bd637d1cacb856959c884ba1c122503fba25769","name":"Salient < 5.5.53 - DOM Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/salient\/salient-5553-dom-cross-site-scripting","description":"The Salient theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2015-06-16"}],"impact":[]},{"uuid":"d860ba20f162e5d3337d3528caa16511d504b8625fe241b17cea0ffef23d35b5","name":"Salient [salient] < 5.5.53","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.5.53","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fd04fd1d-64fb-4502-a91b-fecc2f1ba5a6","name":"Salient Theme &lt;= 4.9 - DOM Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/fd04fd1d-64fb-4502-a91b-fecc2f1ba5a6","description":"The Salient theme comes budled with a vulnerable version of PrettyPhoto which can be found in http:\/\/www.example.com\/wp-content\/themes\/salient\/js\/prettyPhoto.js","date":null}],"impact":[]},{"uuid":"e5fc60bbc757be44020568405280f09c679d666e3a4f666269aa1e086875123c","name":"Salient [salient] < 17.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"17.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-62028","name":"CVE-2025-62028","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-62028","description":"[en] Missing Authorization vulnerability in ThemeNectar Salient salient.This issue affects Salient: from n\/a through < 17.4.0.","date":"2025-11-06"},{"id":"97b32a47c115f731ab06992abeaf428a18d3343e","name":"WordPress Salient Theme < 17.4.0 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/salient\/vulnerability\/wordpress-salient-theme-17-4-0-broken-access-control-vulnerability","description":"<p>WordPress Salient Theme < 17.4.0 is vulnerable to Broken Access Control<\/p><p>Software: Salient<\/p><p>Fixed in version 17.4.0 <\/p><p>Affected Version < 17.4.0<\/p><p>CVE: CVE-2025-62028<\/p>","date":"2025-10-16"},{"id":"4ee415a24bb4c8dd752581c57ab9867dbcf604e7","name":"Salient < 17.4.0 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/salient\/salient-1740-missing-authorization","description":"The Salient | Creative Multipurpose & WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 17.4.0 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.","date":"2025-10-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1760944465"}