Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kentha kentha allows Reflected XSS.This issue affects Kentha: from n/a through <= 4.7.2.
Published: 2026-03-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (Reflected XSS)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that permits reflected cross‑site scripting. When an attacker submits malicious JavaScript and the Kentha theme reflects that input back in the generated HTML without proper escaping, the victim’s browser will execute the script. Based on the nature of XSS, an attacker could potentially hijack the user’s session or collect other sensitive information, but these specific consequences are not stated explicitly in the vendor’s advisory and are inferred.

Affected Systems

QantumThemes Kentha WordPress theme versions up to and including 4.7.2 are affected. Any WordPress installation that has Kentha installed with one of those versions is vulnerable if the theme’s input handling has not been updated.

Risk and Exploitability

The Exploit Prediction Scoring System indicates a very low exploit probability (<1%), and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to provide malicious input that the theme reflects back in a page, most likely through a crafted URL query string or form field. This exploitation path requires that a user visit the malicious link, so the attack relies on social engineering or user interaction, and the CVSS score of 7.1 indicates a high severity and therefore a need for remediation.

Generated by OpenCVE AI on April 28, 2026 at 22:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Kentha theme to the latest available version.
  • If an immediate update is not possible, disable the theme or revert to a previous unaffected version.
  • Consider implementing a Web Application Firewall rule to block scripts in query parameters.

Generated by OpenCVE AI on April 28, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kentha allows Reflected XSS.This issue affects Kentha: from n/a through 4.7.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kentha kentha allows Reflected XSS.This issue affects Kentha: from n/a through <= 4.7.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 20 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Qantumthemes
Qantumthemes kentha
Wordpress
Wordpress wordpress
Vendors & Products Qantumthemes
Qantumthemes kentha
Wordpress
Wordpress wordpress

Thu, 19 Mar 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kentha allows Reflected XSS.This issue affects Kentha: from n/a through 4.7.2.
Title WordPress Kentha theme <= 4.7.2 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Qantumthemes Kentha
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:33:00.862Z

Reserved: 2026-02-02T12:53:40.964Z

Link: CVE-2026-25442

cve-icon Vulnrichment

Updated: 2026-03-19T13:08:30.872Z

cve-icon NVD

Status : Deferred

Published: 2026-03-19T09:16:17.290

Modified: 2026-04-23T15:37:10.400

Link: CVE-2026-25442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T22:30:41Z

Weaknesses