Description
Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an unauthenticated Cross‑Site Scripting (CWE‑79) flaw that allows an attacker to inject and execute arbitrary script code within pages served by the Kids Life | Children School WordPress theme version 5.2 or earlier. The injected script runs in the visitor’s browser context, allowing malicious actions when a user views those pages.

Affected Systems

The issue affects sites using Designthemes Kids Life | Children School WordPress theme versions 5.2 and lower.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity risk, while the EPSS score of less than 1% suggests a very low probability of exploitation. Because the flaw is unauthenticated, any visitor to a page using the vulnerable theme can trigger it; no special privileges are required. The vulnerability is not listed in CISA KEV, so no active exploits have been reported.

Generated by OpenCVE AI on July 22, 2026 at 13:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Kid’s Life | Children School WordPress theme to the latest patch that removes the XSS flaw.
  • If no update is available, deactivate or delete the theme and replace it with a secure alternative.
  • As a temporary measure, ensure that all theme‑generated content is sanitized with WordPress functions such as wp_kses or esc_html until a permanent fix is applied.

Generated by OpenCVE AI on July 22, 2026 at 13:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Designthemes
Designthemes kids Life | Children School Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Designthemes
Designthemes kids Life | Children School Wordpress
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.
Title WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Designthemes Kids Life | Children School Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:48:15.305Z

Reserved: 2026-02-19T09:52:08.215Z

Link: CVE-2026-27402

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')