Junglewise Threat Intelligence

CVE-2026-41557: PressLayouts Kapee Theme unauthenticated XSS

CVE-2026-41557 · Severity: high · CVSS 7.1 · Published 2026-06-17

Vendors: PressLayouts.

Executive brief

The Kapee theme for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs because the theme does not properly sanitize user-provided data, potentially allowing an attacker to redirect visitors to malicious sites or steal sensitive session information. To exploit this, an attacker typically needs to trick a user into clicking a specially crafted link.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the PressLayouts Kapee theme for WordPress in versions prior to 1.7.1. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a crafted URL to a user; if the user visits the link, the attacker's script executes within the context of the user's browser session. This can lead to unauthorized access to session cookies, page defacement, or redirection to malicious domains. The vulnerability is patched in version 1.7.1.

Affected products

  • PressLayouts Kapee < 1.7.1

Timeline

  • 2026-03-02: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
  • 2026-04-23: advisory: Initial Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD
  • 2026-04-23: patched: Version 1.7.1 released to address the vulnerability

References

Related threats