Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes TechOne techone allows Code Injection.This issue affects TechOne: from n/a through <= 3.0.3.
Published: 2026-04-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (Code Injection)
Action: Immediate Update
AI Analysis

Impact

The kutethemes TechOne WordPress theme contains an improper neutralization of script‑related HTML tags that allows attackers to inject arbitrary code through shortcodes. This vulnerability is categorized as a basic cross‑site scripting flaw and can be exploited when a user creates or edits content that includes a crafted shortcode containing malicious scripts. The injected scripts execute in the context of site visitors, potentially compromising their accounts or enabling further attacks.

Affected Systems

Any WordPress site using the TechOne theme up to and including version 3.0.3 is affected. Versions earlier than the theme’s earliest release are also vulnerable because the issue exists from the start of that theme line.

Risk and Exploitability

An attacker who can insert or edit content on the site can create a malicious shortcode that includes script tags. Since the theme fails to sanitize these tags, the code runs when the page is viewed. The risk is high because all authenticated content editors can create such content, and the vulnerability does not require advanced technical knowledge. The extent of impact is limited to the users who view the affected content, but compromised visitors could be tricked into revealing credentials or performing actions on the site. No publicly available exploits are documented, but the inherent ease of crafting a shortcut makes the opportunity for exploitation significant.

Generated by OpenCVE AI on April 8, 2026 at 10:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TechOne theme to version 3.0.4 or later.
  • If an upgrade cannot be performed immediately, disable or remove the vulnerable shortcodes or sanitize shortcode output before rendering.
  • Restrict the user roles that can create or edit content to limit injection opportunities.
  • Keep the WordPress core, the theme, and all plugins up to date.

Generated by OpenCVE AI on April 8, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Kutethemes
Kutethemes techone
Wordpress
Wordpress wordpress
Vendors & Products Kutethemes
Kutethemes techone
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes TechOne techone allows Code Injection.This issue affects TechOne: from n/a through <= 3.0.3.
Title WordPress TechOne theme <= 3.0.3 - Arbitrary Shortcode Execution vulnerability
Weaknesses CWE-80
References

Subscriptions

Kutethemes Techone
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-08T08:30:27.220Z

Reserved: 2026-04-07T10:57:36.650Z

Link: CVE-2026-39625

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T09:16:32.807

Modified: 2026-04-08T21:26:35.910

Link: CVE-2026-39625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:41:50Z

Weaknesses