Description
Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an unauthenticated cross‑site scripting (XSS) vulnerability in the Artale WordPress theme, affecting all versions 2.2.2 and earlier. It allows an attacker to inject arbitrary script code into the context of site visitors. The CVE description does not specify exact consequences, but cross‑site scripting can enable actions such as stealing session cookies, defacing content, or redirecting users to malicious sites – these consequences are inferred from the nature of XSS.

Affected Systems

This issue affects all installations of the ThemeGoods Artale – Wedding Photography WordPress theme that are version 2.2.2 or earlier. Administrators should verify whether they are running a vulnerable version.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score of < 1% indicates a very low probability of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog, so there is no evidence of widespread exploitation yet. The attack vector is likely remote and unauthenticated, requiring an attacker to embed malicious code in content that the theme renders, such as comments or other user‑controlled input. Based on the description, it is inferred that exploitation would allow a remote attacker to inject arbitrary script, potentially leading to cookie theft, session hijacking, defacement, or phishing redirection.

Generated by OpenCVE AI on July 23, 2026 at 16:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Artale theme release, which includes the XSS fix
  • If an upgrade cannot be applied immediately, disable or sanitize any components that accept unsanitized user input, such as comments, reviews, or contact forms
  • Implement a strict Content Security Policy that blocks inline scripts and restricts execution to trusted sources

Generated by OpenCVE AI on July 23, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Themegoods
Themegoods artale | Wedding Photography Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Themegoods
Themegoods artale | Wedding Photography Wordpress
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.
Title WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Themegoods Artale | Wedding Photography Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:50:09.625Z

Reserved: 2025-12-29T11:19:48.753Z

Link: CVE-2025-69152

cve-icon Vulnrichment

Updated: 2026-07-02T12:50:05.572Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T20:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')