Junglewise Threat Intelligence

CVE-2026-4804: ThemeGrill Zakra Stored XSS via post meta values

CVE-2026-4804 · Severity: medium · CVSS 6.4 · Published 2026-07-03

Vendors: ThemeGrill.

Executive brief

The Zakra theme for WordPress, a popular design template for websites, contains a security flaw that allows users with basic contributor permissions to inject malicious scripts into pages. This could lead to unauthorized actions being performed in the browser of any visitor who views the affected page, potentially compromising user sessions or redirecting traffic. The issue affects all versions of the theme up to 4.2.0.

Technical details

The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization of post meta fields (zakra_menu_item_color, zakra_menu_item_hover_color, and zakra_menu_item_active_color). While the classic editor path uses sanitization, the REST API path bypasses it because the fields are registered with 'show_in_rest' => true and 'auth_callback' => '__return_true' without a 'sanitize_callback'. An authenticated attacker with Contributor-level permissions can submit malicious scripts via the REST API, which are then concatenated into CSS strings and output through wp_add_inline_style() without escaping. The vulnerability is addressed in version 4.2.1.

Affected products

  • ThemeGrill Zakra up to, and including, 4.2.0

Timeline

  • 2026-07-03: advisory: NVD publication date
  • 2026-07-03: patched: Version 4.2.1 released to address the issue

References