Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Voldor voldor allows Reflected XSS.This issue affects Voldor: from n/a through 1.0.0.
Published: 2026-10-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Reflected Cross Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

A reflected cross‑site scripting flaw in the Bracketweb Voldor WordPress theme allows malicious input to be reflected back in web pages, enabling attackers to inject and execute arbitrary JavaScript in a victim’s browser. The vulnerability is a classic example of CWE‑79 and can compromise confidentiality and integrity by facilitating session hijacking, defacement, or credential theft. Attackers can exploit this flaw without needing special credentials, simply by crafting a URL or embedding malicious input where the theme renders it.

Affected Systems

WordPress sites that use the Bracketweb Voldor theme, versions from the first released build through 1.0.0 inclusive. No further version is currently identified as affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact and medium exploitation complexity. With the EPSS score unavailable, the likelihood of exploitation is uncertain but the presence of a reflected XSS vector means attackers can target any user who visits a crafted page. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Nonetheless, the attack path—sending a malicious link to a user or embedding a crafted URL in a content page—makes it straightforward for an attacker to exploit this flaw.

Generated by OpenCVE AI on October 9, 2026 at 15:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Voldor theme to the latest available version that addresses the input sanitization issue.
  • If an immediate update is not possible, apply a temporary workaround by adding a sanitization filter in the theme’s functions.php to escape any output rendered by the vulnerable logic, thereby mitigating the reflected XSS risk.
  • Configure a browser Content Security Policy header that limits script execution to trusted sources, reducing the impact of any reflected XSS payload.

Generated by OpenCVE AI on October 9, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 13:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Voldor voldor allows Reflected XSS.This issue affects Voldor: from n/a through 1.0.0.
Title WordPress Voldor theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T13:00:16.560Z

Reserved: 2026-09-20T00:21:51.840Z

Link: CVE-2026-94060

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T13:17:11.880

Modified: 2026-10-09T13:20:48.273

Link: CVE-2026-94060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T15:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')