Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheBi thebi allows Reflected XSS.This issue affects TheBi: from n/a through <= 1.0.5.
Published: 2026-03-05
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (Reflected XSS)
Action: Apply Patch
AI Analysis

Impact

The flaw originates from improper neutralization of user input during page rendering in the WordPress TheBi theme. It enables an attacker to inject arbitrary JavaScript that executes in a victim’s browser when the corresponding page is displayed. Attackers can leverage this to steal session cookies, deface content, or deliver malware. The vulnerability affects the theme as well as any earlier releases, meaning that sites running the vulnerable theme are exposed to the potential of code injection within the rendered page. The likely attack vector involves a crafted link that, when visited by a user, triggers the malicious payload; this is inferred from the reflected nature of the XSS and the requirement for user interaction.

Affected Systems

All installations of the foreverpinetree TheBi theme with version 1.0.5 or older are impacted. Sites that use this theme and have not applied a later update are therefore at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity flaw. The EPSS metric of less than 1% suggests the likelihood of exploitation in the immediate future is low, and the vulnerability does not appear in CISA's KEV catalog. Typical exploitation would involve a malicious or crafted link that, when followed by a victim, causes the reflected payload to execute. This approach requires user interaction, and is inferred from the nature of reflected XSS; attackers do not need elevated privileges on the host. The threat is confined to user interactions with inadvertently loaded content; attackers do not appear to require elevated privileges on the host.

Generated by OpenCVE AI on April 17, 2026 at 12:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WordPress TheBi theme to a release newer than 1.0.5, which removes the reflected XSS flaw.
  • If an updated theme is unavailable, remove or deactivate the theme to eliminate the vulnerable code path.
  • Implement content‑security‑policy headers or deploy a web‑application firewall that blocks or sanitizes suspicious script content to provide a temporary shield against reflected XSS attacks.

Generated by OpenCVE AI on April 17, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 09 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Foreverpinetree
Foreverpinetree thebi
Wordpress
Wordpress wordpress
Vendors & Products Foreverpinetree
Foreverpinetree thebi
Wordpress
Wordpress wordpress

Thu, 05 Mar 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheBi thebi allows Reflected XSS.This issue affects TheBi: from n/a through <= 1.0.5.
Title WordPress TheBi theme <= 1.0.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Foreverpinetree Thebi
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:13:50.593Z

Reserved: 2026-01-07T12:22:12.277Z

Link: CVE-2026-22438

cve-icon Vulnrichment

Updated: 2026-03-09T16:24:18.005Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-05T06:16:18.270

Modified: 2026-03-09T17:16:15.647

Link: CVE-2026-22438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T13:00:12Z

Weaknesses