Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7.
Published: 2025-03-26
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during page generation leads to a stored cross‑site scripting vulnerability (CWE‑79) in the 99colorthemes RainbowNews WordPress theme. This flaw allows an attacker to inject malicious JavaScript that is persisted in the database and executed whenever a visitor loads a page that renders the affected content. The injected script can perform actions such as stealing session cookies, redirecting users, defacing the site, or delivering malware. The impact is primarily a compromise of user confidentiality and integrity, and the vulnerability can affect any user who views the compromised page.

Affected Systems

The vulnerability is present in all releases of the RainbowNews theme up to and including version 1.0.7. WordPress installations that have deployed this theme, regardless of the WordPress core version, are affected. The issue is tied to the theme's handling of user‑supplied input, not to the underlying PHP or database layer.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EPSS value of less than 1% suggests the likelihood of exploitation is currently low. Because the flaw is stored XSS, an attacker simply needs to supply content that will be rendered by the theme; no elevated credentials or privileged permissions are required. The flaw does not appear in the CISA KEV catalog, but the potential for widespread damage remains if an attacker targets a high‑traffic WordPress site running the affected theme.

Generated by OpenCVE AI on May 2, 2026 at 08:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest official update to the RainbowNews theme that resolves the XSS flaw.
  • If an update is not yet available, switch to a different, actively maintained theme or disable RainbowNews entirely until a fix is released.
  • Implement a web application firewall or content security policy that blocks or sanitizes unauthorized script payloads, and review existing theme content for injected JavaScript.

Generated by OpenCVE AI on May 2, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8211 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7.
History

Tue, 28 Apr 2026 19:30:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews rainbownews allows Stored XSS.This issue affects RainbowNews: from n/a through <= 1.0.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews rainbownews allows Stored XSS.This issue affects RainbowNews: from n/a through <= 1.0.7.
References

Wed, 26 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 99colorthemes RainbowNews allows Stored XSS.This issue affects RainbowNews: from n/a through 1.0.7.
Title WordPress RainbowNews theme <= 1.0.7 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:39.871Z

Reserved: 2025-02-14T06:53:10.325Z

Link: CVE-2025-26747

cve-icon Vulnrichment

Updated: 2025-03-26T15:24:41.408Z

cve-icon NVD

Status : Deferred

Published: 2025-03-26T15:16:12.390

Modified: 2026-04-28T19:29:44.133

Link: CVE-2025-26747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')