Executive brief
The NativeChurch theme for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs when a user clicks on a specially crafted link, potentially leading to unauthorized actions being performed in the user's browser, such as redirecting visitors to malicious sites or stealing session information. Because this affects a theme used for public-facing websites, it can damage a site's reputation and compromise visitor security.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the NativeChurch WordPress theme (versions <= 4.8.8.2) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to the theft of sensitive information like session cookies or the performance of unauthorized actions on behalf of the user. As of the advisory date, no official patch has been released by the developer.
Affected products
- imithemes (Patchstack) NativeChurch <= 4.8.8.2
Timeline
- 2025-11-05: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
- 2026-06-30: advisory: Patchstack published advisory details
- 2026-07-02: disclosed: CVE-2026-27408 published to the NVD dataset