Executive brief
The TechOne WordPress theme by kutethemes contains a security flaw that allows unauthorized individuals to inject malicious scripts or content into the website. This theme is used to build and design WordPress-based websites; an exploit could lead to the defacement of the site, the creation of phishing pages, or the redirection of visitors to malicious websites. This can damage a company's reputation and put its customers' data at risk.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the kutethemes TechOne theme for WordPress (versions up to and including 3.0.3) due to improper neutralization of script-related HTML tags. The flaw allows an unauthenticated remote attacker to perform content injection and arbitrary shortcode execution. By sending a specially crafted request, an attacker can inject malicious scripts that execute in the context of a user's browser or inject unauthorized content into pages and posts. As of the advisory date, no official patch has been released.
Affected products
- kutethemes TechOne <= 3.0.3
Timeline
- 2026-01-12: other: Vulnerability reported by researcher
- 2026-02-11: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD