Description
Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
Published: 2026-07-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated cross‑site scripting flaw exists in the Manual – Documentation, Knowledge Base & Education WordPress Theme up to version 7.5.4. The vulnerability allows an attacker to insert arbitrary JavaScript into pages generated by the theme, enabling the execution of scripts in the browsers of site visitors. Because no authentication is required, any user who accesses a vulnerable page can trigger the flaw.

Affected Systems

All installations of the PixelaceHQ Manual theme version 7.5.4 and earlier are affected. Sites that enable or activate this theme are at risk until the theme is updated or removed.

Risk and Exploitability

The CVSS score is 7.1, indicating a high impact, while the EPSS score of less than 1 % suggests that exploitation opportunities in the wild are currently low. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by simply visiting a page that includes the vulnerable rendering logic; no credentials or additional access privileges are necessary, making the vulnerability readily usable against site visitors and the site itself.

Generated by OpenCVE AI on August 3, 2026 at 21:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Manual theme to version 7.5.5 or later, which contains the security fix for the XSS issue.
  • If a theme upgrade cannot be performed immediately, implement a Content Security Policy that restricts inline scripts and limits execution to trusted sources to reduce the risk of the injected code running.
  • If the theme is not essential to the website’s functionality, consider disabling or removing it entirely to eliminate the vulnerable code path.

Generated by OpenCVE AI on August 3, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Pixelacehq
Pixelacehq manual - Documentation, Knowledge Base & Education Wordpress Theme
Wordpress
Wordpress wordpress
Vendors & Products Pixelacehq
Pixelacehq manual - Documentation, Knowledge Base & Education Wordpress Theme
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
Title WordPress Manual - Documentation, Knowledge Base & Education WordPress Theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Pixelacehq Manual - Documentation, Knowledge Base & Education Wordpress Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:26:54.308Z

Reserved: 2026-07-22T08:53:52.510Z

Link: CVE-2026-65511

cve-icon Vulnrichment

Updated: 2026-07-23T13:26:49.737Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:44.130

Modified: 2026-07-23T14:17:55.637

Link: CVE-2026-65511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')