Junglewise Threat Intelligence

CVE-2026-39642: SpabRice Nyla Cross-Site Scripting and Content Injection

CVE-2026-39642 · Severity: medium · CVSS 5.3 · Published 2026-05-26

Executive brief

The Nyla theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to inject malicious code or content into the website. This could lead to the display of fraudulent information, phishing pages, or the redirection of visitors to malicious sites. As of the latest report, there is no official patch available to fix this issue.

Technical details

A vulnerability classified as Improper Neutralization of Script-Related HTML Tags (CWE-80) exists in the SpabRice Nyla theme for WordPress through version 1.7. The flaw allows for basic Cross-Site Scripting (XSS) and arbitrary shortcode execution. An unauthenticated remote attacker can exploit this by sending specially crafted requests to inject malicious scripts or content into web pages. This can result in unauthorized content modification or the execution of client-side scripts in the context of a user's browser. No official patch has been released at the time of disclosure.

Affected products

  • SpabRice Nyla n/a through 1.7

Timeline

  • 2026-01-15: other: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-05-26: advisory: Published by Patchstack and NVD

References