Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection.

This issue affects Nyla: from n/a through 1.7.
Published: 2026-05-26
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This CVE describes a basic cross‑site scripting flaw in the SpabRice Nyla WordPress theme, versions up through 1.7. The vulnerability stems from the theme's failure to neutralize script‑related HTML tags within rendered shortcodes, allowing attackers to inject malicious code into web pages. The flaw is classified as CWE‑80, where improper input sanitization permits arbitrary injection of executable scripts that can compromise user sessions, data integrity, and site reputation.

Affected Systems

The issue affects every deployment of the Nyla theme manufactured by SpabRice that is running a version equal to or older than 1.7. Sites that have not upgraded beyond this release are therefore exposed, irrespective of other WordPress configuration or security measures.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity level, and the EPSS score is currently unavailable, suggesting no readily measurable recent exploitation activity. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker placing malicious content through the WordPress content editor or any interface that processes the theme's shortcodes; only users with permission to edit posts or pages would typically be able to inject the harmful code. Successful exploitation would enable the attacker to run arbitrary JavaScript in the context of site visitors, leading to potential credential theft or phishing. The risk is therefore primarily a code‑execution threat that could be amplified by social engineering or by the visitor’s browser context.

Generated by OpenCVE AI on May 26, 2026 at 10:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Nyla theme to the latest patched version that removes the unsanitized shortcode rendering
  • If an upgrade cannot be performed immediately, identify the specific shortcode that allows raw HTML or JS and disable it or configure the theme to strip disallowed tags from its output
  • Restrict content‑editing privileges so that only trusted administrators can insert shortcodes that render user‑supplied content

Generated by OpenCVE AI on May 26, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Spabrice
Spabrice nyla
Wordpress
Wordpress wordpress
Vendors & Products Spabrice
Spabrice nyla
Wordpress
Wordpress wordpress

Tue, 26 May 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a through 1.7.
Title WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Spabrice Nyla
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-26T10:47:43.756Z

Reserved: 2026-04-07T10:57:43.491Z

Link: CVE-2026-39642

cve-icon Vulnrichment

Updated: 2026-05-26T10:47:39.226Z

cve-icon NVD

Status : Received

Published: 2026-05-26T09:16:20.487

Modified: 2026-05-26T09:16:20.487

Link: CVE-2026-39642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T12:59:38Z

Weaknesses