Executive brief
The Kids Zone WordPress theme, used for children-oriented websites, contains a security flaw that allows attackers to inject malicious scripts into the site. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. As of the latest report, there is no official patch available from the developer.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Kids Zone - Children WordPress Theme through version 5.4 due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is exploitable by unauthenticated remote attackers but requires user interaction, such as a victim clicking a malicious link. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. No official patch has been released by the vendor, though third-party mitigation rules are available.
Affected products
- Design themes Kids Zone - Children WordPress Theme <= 5.4
Timeline
- 2025-11-07: disclosed: Reported by João Pedro S Alcântara (Kinorth)
- 2026-06-30: advisory: Patchstack published advisory details
- 2026-07-02: advisory: CVE published to NVD dataset