Executive brief
Skillate, a WordPress theme used for building online learning and marketplace websites, contains a security flaw that allows attackers to execute malicious scripts. By tricking a user into clicking a specially crafted link, an attacker can steal session information, redirect visitors to malicious sites, or deface the website. This vulnerability can be exploited by anyone on the internet without needing an account on the affected site.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Themeum Skillate theme for WordPress due to insufficient input sanitization and output escaping. An unauthenticated remote attacker can exploit this by sending a crafted URL to a victim; when the victim visits the link, the malicious script is executed in the context of their browser session. This can lead to the theft of sensitive information, such as session cookies, or the performance of unauthorized actions on behalf of the user. The vulnerability affects all versions up to 1.2.10, and as of the advisory date, no official patch has been released.
Affected products
- Themeum Skillate <= 1.2.10
Timeline
- 2025-09-18: other: Vulnerability reported by researcher to Patchstack
- 2026-01-13: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: CVE published in the National Vulnerability Database (NVD)