Description
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
Published: 2026-08-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CozyStay theme for WordPress contains an unauthenticated cross‑site scripting vulnerability that allows attackers to inject malicious JavaScript into pages rendered by the theme. By placing arbitrary script payloads into areas of the site that are not properly sanitised, an attacker can execute code within a visitor’s browser, potentially leading to session hijacking, defacement, or theft of sensitive information. The weakness is a classic input‑validation flaw, classified as CWE‑79.

Affected Systems

WordPress installations running the CozyStay theme version 1.10.0 or earlier are affected. The vendor is LoftOcean and the product name is CozyStay. Users should review their WordPress theme version and ensure it is updated to 1.10.1 or later.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity impact and the vulnerability is exploitable without authentication, making it accessible to any visitor who triggers the vulnerable code path. EPSS data is currently unavailable, but the lack of a KEV listing suggests it is not yet a widely leveraged exploit. The likely attack vector is remote, via a web request to a page that renders the vulnerable theme components. An attacker does not need privileged access to the site, raising the risk to all sites that feature CozyStay.

Generated by OpenCVE AI on August 27, 2026 at 10:51 UTC.

Remediation

Vendor Solution

Update the WordPress CozyStay Theme to the latest available version (at least 1.10.1).


OpenCVE Recommended Actions

  • Update the WordPress CozyStay Theme to the latest available version (at least 1.10.1).
  • If an immediate update is not possible, deactivate the CozyStay theme and switch to a secure alternative theme.
  • Install and configure a reputable WordPress security plugin that includes an XSS protection module to block or sanitize malicious scripts until the theme is patched.

Generated by OpenCVE AI on August 27, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Loftocean
Loftocean cozystay
Wordpress
Wordpress wordpress
Vendors & Products Loftocean
Loftocean cozystay
Wordpress
Wordpress wordpress

Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
Title WordPress CozyStay theme <= 1.10.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Loftocean Cozystay
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-27T12:17:17.638Z

Reserved: 2026-08-24T07:38:18.805Z

Link: CVE-2026-78289

cve-icon Vulnrichment

Updated: 2026-08-27T12:17:12.047Z

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:38.393

Modified: 2026-08-27T13:18:37.940

Link: CVE-2026-78289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T13:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')