Junglewise Threat Intelligence

CVE-2026-39629: Kutethemes Uminex XSS and Content Injection

CVE-2026-39629 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Vendors: KuteThemes.

Executive brief

The Uminex theme for WordPress contains a security flaw that allows unauthorized individuals to inject malicious scripts or content into the website. This could lead to the creation of phishing pages or the redirection of visitors to harmful sites, potentially damaging the site's reputation and compromising user data. The vulnerability is present in all versions up to and including 1.0.9.

Technical details

A vulnerability classified as Improper Neutralization of Script-Related HTML Tags (CWE-80) exists in the Kutethemes Uminex theme for WordPress. The flaw allows for basic Cross-Site Scripting (XSS) and arbitrary shortcode execution due to insufficient input validation and output sanitization. An unauthenticated remote attacker can exploit this to inject malicious scripts or content into pages and posts. The issue affects all versions up to and including 1.0.9. As of the advisory date, no official patch has been released.

Affected products

  • Kutethemes Uminex <= 1.0.9

Timeline

  • 2026-01-13: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-02-12: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References