Junglewise Threat Intelligence

CVE-2026-39625: kutethemes TechOne Cross-Site Scripting and Content Injection

CVE-2026-39625 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Vendors: KuteThemes.

Executive brief

The TechOne WordPress theme by kutethemes contains a security flaw that allows unauthorized individuals to inject malicious scripts or content into the website. This theme is used to build and design WordPress-based websites; an exploit could lead to the defacement of the site, the creation of phishing pages, or the redirection of visitors to malicious websites. This can damage a company's reputation and put its customers' data at risk.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the kutethemes TechOne theme for WordPress (versions up to and including 3.0.3) due to improper neutralization of script-related HTML tags. The flaw allows an unauthenticated remote attacker to perform content injection and arbitrary shortcode execution. By sending a specially crafted request, an attacker can inject malicious scripts that execute in the context of a user's browser or inject unauthorized content into pages and posts. As of the advisory date, no official patch has been released.

Affected products

  • kutethemes TechOne <= 3.0.3

Timeline

  • 2026-01-12: other: Vulnerability reported by researcher
  • 2026-02-11: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References