Description
Unauthenticated Cross Site Scripting (XSS) in Jannah <= 7.6.5 versions.
Published: 2026-10-10
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross Site Scripting execution in user browsers
Action: Patch Theme
AI Analysis

Impact

An unauthenticated cross‑site scripting flaw exists in the TieLabs Jannah WordPress theme versions up to 7.6.5. The flaw allows an attacker to inject and execute arbitrary JavaScript in the context of any visitor’s browser that loads a page rendered by the vulnerable theme. This vulnerability is classified as CWE‑79.

Affected Systems

The theme that is affected is the TieLabs Jannah WordPress theme, specifically any installation using version 7.6.5 or earlier. Users who have not upgraded the theme to a later release are at risk.

Risk and Exploitability

The CVSS score of 7.1 reflects a high severity rating. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so exploitation frequency is uncertain. Because the flaw can be triggered without authentication and only requires a visitor to load a page rendered by the affected theme, attackers can embed malicious scripts directly into the page content.

Generated by OpenCVE AI on October 10, 2026 at 21:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Jannah theme version 7.6.6 or later, which includes the XSS fix.
  • Inspect and sanitize any legacy content or custom input that may still contain the vulnerable code, removing any injected scripts.
  • Deploy a security plugin that enforces proper input validation and output escaping, and configure a Content Security Policy to mitigate future XSS attempts.

Generated by OpenCVE AI on October 10, 2026 at 21:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Jannah <= 7.6.5 versions.
Title WordPress Jannah theme <= 7.6.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:37:19.260Z

Reserved: 2026-04-29T09:05:01.790Z

Link: CVE-2026-42693

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:35.193

Modified: 2026-10-10T20:16:35.193

Link: CVE-2026-42693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T21:15:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')