Junglewise Threat Intelligence

CVE-2026-27430: tranmautritam TheFox unauthenticated reflected XSS

CVE-2026-27430 · Severity: high · CVSS 7.1 · Published 2026-07-02

Executive brief

TheFox, a popular multi-purpose WordPress theme, contains a security flaw that allows attackers to execute malicious scripts in the browsers of other users. By tricking a site visitor or administrator into clicking a specially crafted link, an attacker could steal login sessions, redirect users to fraudulent websites, or deface the site's content. This vulnerability is particularly concerning as it does not require the attacker to have an account on the target website.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the TheFox WordPress theme (versions <= 3.9.76) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript into the context of a victim's browser session. Exploitation requires a victim to interact with a malicious link or crafted request (User Interaction: Required). Successful exploitation can lead to session hijacking, unauthorized actions on behalf of the user, or information disclosure. As of the advisory date, no official patch has been released by the developer.

Affected products

  • tranmautritam TheFox <= 3.9.76

Timeline

  • 2025-10-17: disclosed: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-06-29: advisory: Initial advisory published by Patchstack
  • 2026-07-02: advisory: CVE published to NVD dataset

References

Related threats