Back to Database
Status published
Medium
CVE-2017-13138
DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme...
Vulnerability Description
DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-13138
Credits & Attribution
No credits recorded in the NVD database.
References
More from qodeinteractive
View All →CVE-2025-8146
Qi Addons for Elementor <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via TypeOut Text Widget
Medium
6.4
CVE-2025-6252
Qi Addons For Elementor <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Medium
6.4
CVE-2025-13157
QODE Wishlist for WooCommerce <= 1.2.7 - Unauthenticated Insecure Direct Object Reference to Wishlist Update
Medium
5.3
CVE-2025-12182
Qi Blocks <= 1.4.3 - Missing Authorization to Arbitrary Attachment Resize
Medium
4.3
CVE-2025-12180
Qi Blocks <= 1.4.3 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Update
Medium
4.3
Affected Vendor
qodeinteractive
View all reports →Affected Software
bridge
Vulnerable Versions:
0
Timeline
Official Publish:
August 23rd, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.