Executive brief
Themify Folo, a theme used for WordPress websites, contains a security flaw that allows attackers to execute malicious scripts in a user's browser. By tricking a site visitor or administrator into clicking a specially crafted link, an attacker could steal login sessions, redirect users to fraudulent websites, or deface the site's appearance. This vulnerability poses a risk to both site operations and the privacy of its visitors.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Themify Folo theme for WordPress (versions <= 1.9.6) due to insufficient sanitization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by persuading a user to visit a malicious URL containing a crafted payload. If successful, the attacker can execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. As of the advisory date, no official patch has been released, and users are advised to use third-party mitigation rules or monitor for updates.
Affected products
- Themify Folo n/a through 1.9.6
Timeline
- 2025-03-20: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
- 2025-04-01: advisory: Initial disclosure by Patchstack
- 2026-06-17: disclosed: NVD publication date