Description
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
Published: 2026-08-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated attacker can exploit a reflected XSS flaw in the WordPress Urna theme when its version is 2.6.2 or older. The flaw allows injection of arbitrary client‑side scripts that run in the browser of any visitor to the affected site, potentially enabling cookie theft, session hijacking, defacement, or delivery of malicious payloads. This weakness is classified as CWE‑79, indicating an input validation weakness that fails to encode or filter user‑supplied data.

Affected Systems

The vulnerability is limited to installations of the Urna theme provided by thembay. Any WordPress site using Urna version 2.6.2 or earlier is affected. Versions 2.6.3 and newer contain the fix and are not vulnerable.

Risk and Exploitability

The CVSS score of 7.1 marks the issue as High. No EPSS score is available, so the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated user supplying malicious script payloads via a specially crafted request that the theme renders unsanitized.

Generated by OpenCVE AI on August 24, 2026 at 13:50 UTC.

Remediation

Vendor Solution

Update the WordPress Urna Theme to the latest available version (at least 2.6.3).


OpenCVE Recommended Actions

  • Upgrade the Urna theme to version 2.6.3 or later.
  • If immediate upgrade is not possible, deactivate the Urna theme and switch to a safe default or alternative theme until the fix is available.
  • Conduct a site‑wide scan to remove injected scripts and review recent content for malicious modifications.
  • Implement a Web Application Firewall rule or content filter to block suspected XSS payloads targeting the theme’s input parameters.

Generated by OpenCVE AI on August 24, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Thembay
Thembay urna
Wordpress
Wordpress wordpress
Vendors & Products Thembay
Thembay urna
Wordpress
Wordpress wordpress

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
Title WordPress Urna theme <= 2.6.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T12:51:06.469Z

Reserved: 2026-07-27T14:00:13.422Z

Link: CVE-2026-66610

cve-icon Vulnrichment

Updated: 2026-08-24T12:47:41.189Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T12:16:53.127

Modified: 2026-08-24T16:40:53.647

Link: CVE-2026-66610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T14:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')