Description
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
Published: 2026-08-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Aora theme for WordPress versions 1.3.19 and earlier contains an unauthenticated Cross‑Site Scripting flaw. Unsanitized input in the theme’s code allows attackers to inject arbitrary scripts that run in the browsers of visitors who load a page using the vulnerable theme. This can lead to session hijacking, credential theft, or defacement of the site.

Affected Systems

WordPress installations using the thembay Aora theme version 1.3.19 or earlier are affected. Users who have not upgraded to 1.3.20 or later remain vulnerable and must apply the update immediately.

Risk and Exploitability

The CVSS score of 7.1 marks this as high severity. Exploit probability is not quantified due to a missing EPSS score, and the vulnerability is not listed in CISA’s KEV catalog. Attackers do not need any form of privilege or authentication, and can target the site merely by delivering a malicious payload to a web page that uses the theme.

Generated by OpenCVE AI on August 20, 2026 at 21:46 UTC.

Remediation

Vendor Solution

Update the WordPress Aora Theme to the latest available version (at least 1.3.20).


OpenCVE Recommended Actions

  • Upgrade the Aora theme to version 1.3.20 or higher.
  • If an update cannot be performed immediately, disable or uninstall the Aora theme to prevent exploitation.
  • As an additional safeguard, implement a strict Content‑Security‑Policy header to block execution of inline scripts.

Generated by OpenCVE AI on August 20, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Thembay
Thembay aora
Wordpress
Wordpress wordpress
Vendors & Products Thembay
Thembay aora
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
Title WordPress Aora theme <= 1.3.19 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T18:42:34.799Z

Reserved: 2026-07-27T14:00:13.422Z

Link: CVE-2026-66612

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:34.813

Modified: 2026-08-20T19:16:58.350

Link: CVE-2026-66612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T22:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')