Executive brief
The Prague plugin for WordPress, used for site design and layout, contains a security flaw that allows attackers to inject malicious scripts into the website. This occurs when a user clicks on a specially crafted link, potentially leading to unauthorized actions being performed in the user's browser, such as redirecting them to malicious sites or stealing session information. Site administrators should update to version 2.2.9 to resolve this issue.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Fox-themes Prague plugin for WordPress (versions <= 2.2.8) due to improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions if the victim is a site administrator. The issue is addressed in version 2.2.9.
Affected products
- Fox-themes Prague Plugins <= 2.2.8
Timeline
- 2025-11-15: other: Reported by João Pedro S Alcântara (Kinorth)
- 2026-01-27: disclosed: Initial disclosure by Patchstack
- 2026-06-03: advisory: NVD publication date