Junglewise Threat Intelligence

CVE-2026-39626: kutethemes Armania XSS and Content Injection

CVE-2026-39626 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Vendors: KuteThemes.

Executive brief

The Armania WordPress theme is vulnerable to a security flaw that allows unauthorized individuals to inject malicious code or content into the website. This could lead to the display of fraudulent information, phishing pages, or the execution of unauthorized scripts in a visitor's browser. Because this affects the visual and functional integrity of the site, it could damage a company's reputation or be used to deceive customers.

Technical details

A vulnerability exists in the kutethemes Armania theme (versions up to and including 1.4.8) due to improper neutralization of script-related HTML tags. This flaw allows an unauthenticated remote attacker to perform Cross-Site Scripting (XSS) and arbitrary shortcode execution. The root cause is a failure to sufficiently sanitize user-supplied input before rendering it in a web page. An attacker can exploit this to inject malicious scripts or content, potentially leading to session hijacking or the creation of phishing pages. As of the advisory date, no official patch has been released.

Affected products

  • kutethemes Armania <= 1.4.8

Timeline

  • 2026-01-12: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-02-11: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE-2026-39626 published

References