Description
Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Patch Now
AI Analysis

Impact

This vulnerability is an unauthenticated Cross‑Site Scripting (CWE‑79) flaw that allows an attacker to inject and execute arbitrary script code within pages served by the Kids Life | Children School WordPress theme version 5.2 or earlier. The injected script runs in the visitor’s browser context, allowing malicious actions when a user views those pages.

Affected Systems

The issue affects sites using Designthemes Kids Life | Children School WordPress theme versions 5.2 and lower.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity risk, while the EPSS score of less than 1% suggests a very low probability of exploitation. Because the flaw is unauthenticated, any visitor to a page using the vulnerable theme can trigger it; no special privileges are required. The vulnerability is not listed in CISA KEV, so no active exploits have been reported.

Generated by OpenCVE AI on July 31, 2026 at 15:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Kid’s Life | Children School WordPress theme to the latest patch that removes the XSS flaw.
  • If no update is available, deactivate or delete the theme and replace it with a secure alternative.
  • As a temporary measure, ensure that all theme‑generated content is sanitized with WordPress functions such as wp_kses or esc_html until a permanent fix is applied.

Generated by OpenCVE AI on July 31, 2026 at 15:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Designthemes
Designthemes kids Life | Children School Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Designthemes
Designthemes kids Life | Children School Wordpress
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.
Title WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Designthemes Kids Life | Children School Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:48:15.305Z

Reserved: 2026-02-19T09:52:08.215Z

Link: CVE-2026-27402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-07-02T12:16:59.817

Modified: 2026-07-02T13:58:23.330

Link: CVE-2026-27402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T15:15:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')