Description
Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Cross Site Scripting vulnerability exists in the Word7 allows arbitrary into web pages viewed by site visitors. Based on the description, it is inferred that user input may not be properly sanitized, giving an attacker the ability to execute JavaScript when the page is rendered.

Affected Systems

All releases of DesignThemes' Trendy Travel WordPress theme through version 6.7 are affected. Site owners who have not upgraded beyond 6.7 are at risk.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as high severity, but the EPSS score of <1% indicates a very low current likelihood. The attack vector is remote, via crafted URLs or form inputs that cause the browser to render untrusted data, allowing the execution of malicious JavaScript in the context of site visitors.

Generated by OpenCVE AI on July 17, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Trendy Travel theme release (≥6.8).
  • If an upgrade cannot be performed immediately, disable or modify any theme components that accept user‑supplied input and ensure all output is properly escaped.
  • Deploy a content security policy that restricts inline scripts and limits origins, reducing the impact of an XSS flaw until the theme is updated.

Generated by OpenCVE AI on July 17, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Designthemes
Designthemes trendy Travel
Wordpress
Wordpress wordpress
Vendors & Products Designthemes
Designthemes trendy Travel
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
Title WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Designthemes Trendy Travel
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:44:40.367Z

Reserved: 2025-12-29T11:19:48.753Z

Link: CVE-2025-69153

cve-icon Vulnrichment

Updated: 2026-07-02T14:44:35.565Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T11:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')