Description
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Cross Site Scripting vulnerability exists in the Kids Zone – Children WordPress Theme versions up to 5.4. The flaw allows an attacker to inject and execute arbitrary JavaScript when a page that uses the vulnerable theme is rendered. Because the code runs in the context of any site visitor, it can manipulate the page, steal data from the browser, or perform other malicious actions within that browser session.

Affected Systems

The theme version 5.4 and earlier from the Design Themes publisher. Any WordPress installation that has applied the Kids Zone – Children WordPress Theme with those versions is affected.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score of <1% indicates that unauthenticated, allowing any visitor to trigger the XSS if they can access a page that uses the theme. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 21, 2026 at 12:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Kids Zone – Children WordPress Theme to version 5.5 or later
  • If an immediate update is not possible, switch to a different theme or disable the vulnerable theme to eliminate the XSS surface
  • Scan the site for injected scripts, remove any malicious content, and perform a security audit to ensure the site is clean
  • Monitor logs and user activity for signs of XSS exploitation and investigate any suspicious behavior

Generated by OpenCVE AI on July 21, 2026 at 12:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Design Themes
Design Themes kids Zone - Children Wordpress Theme
Wordpress
Wordpress wordpress
Vendors & Products Design Themes
Design Themes kids Zone - Children Wordpress Theme
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
Title WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Design Themes Kids Zone - Children Wordpress Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T15:53:51.784Z

Reserved: 2025-12-29T11:19:54.137Z

Link: CVE-2025-69156

cve-icon Vulnrichment

Updated: 2026-07-02T13:33:40.097Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:15:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')