Junglewise Threat Intelligence

CVE-2025-52739: WordPress Sala theme reflected XSS

CVE-2025-52739 · Severity: high · CVSS 7.1 · Published 2025-12-31

Vendors: Wordpress.

Executive brief

The Sala WordPress theme contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts into web pages viewed by site visitors. An attacker can craft a malicious link and trick an authenticated user into clicking it, enabling the attacker to steal visitor data, hijack user accounts, or deface the website. The vulnerability affects all versions up to 1.1.3 with no official patch currently available.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability in the WordPress Sala theme caused by improper input neutralization during web page generation. The vulnerability allows unauthenticated attackers to inject malicious JavaScript that executes in the context of a user's browser. Exploitation requires user interaction (a victim must click a crafted link or visit a malicious page), and the injected script can steal sensitive data such as session cookies or account credentials. No official patch has been released as of the advisory date; Patchstack has issued mitigation rules as a temporary workaround.

Affected products

  • WordPress Sala theme up to 1.1.3

Timeline

  • 2025-08-04: disclosed
  • 2025-12-31: advisory

References