Description
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
Published: 2026-08-18
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Templately plugin for WordPress contains an input validation flaw that permits any visitor to inject arbitrary JavaScript into pages served by the site. Because the flaw is unauthenticated, an attacker can deliver a crafted URL or upload content that triggers the cross‑site scripting, potentially hijacking user sessions, stealing credentials, or loading malicious payloads. The weakness is identified as CWE‑79 and carries a high severity with a CVSS score of 7.1.

Affected Systems

The vulnerability exists in WPDeveloper’s Templately plugin for WordPress, affecting all releases through version 3.7.1. Sites that have not upgraded to 3.7.2 or later remain vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level. While the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the unauthenticated nature of the XSS flaw means that attackers can exploit it from any source. Likely attack paths involve a malicious link or input that the plugin fails to sanitize, causing script execution in the browsers of any site visitor. Administrators should regard this as a significant risk, especially on publicly exposed sites, and remediate promptly.

Generated by OpenCVE AI on August 18, 2026 at 16:28 UTC.

Remediation

Vendor Solution

Update the WordPress Templately plugin to the latest available version (at least 3.7.2).


OpenCVE Recommended Actions

  • Update the Templately plugin to version 3.7.2 or newer from the official repository.
  • If an update is not immediately possible, deactivate the plugin to prevent exposure while waiting for a fix.
  • Review the WordPress site’s security configuration by enabling a content‑security policy, restricting user input, and monitoring for abnormal script activity.

Generated by OpenCVE AI on August 18, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
Title WordPress Templately plugin <= 3.7.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T15:03:18.743Z

Reserved: 2026-07-27T14:00:48.793Z

Link: CVE-2026-66667

cve-icon Vulnrichment

Updated: 2026-08-18T15:03:05.996Z

cve-icon NVD

Status : Received

Published: 2026-08-18T15:16:59.693

Modified: 2026-08-18T15:16:59.693

Link: CVE-2026-66667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')