Junglewise Threat Intelligence

CVE-2026-48869: Kriesi Enfold unauthenticated XSS

CVE-2026-48869 · Severity: high · CVSS 7.1 · Published 2026-06-17

Executive brief

Enfold is a popular premium theme used to design and build WordPress websites. A security flaw allows unauthenticated attackers to trick a site administrator or visitor into executing malicious scripts by clicking a specially crafted link. This could lead to unauthorized actions being performed in the user's session, such as redirecting visitors to malicious sites or stealing sensitive session information.

Technical details

The Enfold theme for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a crafted URL to a victim. If the victim (such as a site administrator) clicks the link, the malicious script executes within the context of their browser session. This can allow the attacker to access cookies, session tokens, or perform actions on behalf of the user. The vulnerability is patched in version 7.1.5.

Affected products

  • Kriesi Enfold <= 7.1.4

Timeline

  • 2026-04-11: other: Vulnerability reported by researcher Kinorth
  • 2026-06-01: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD

References

Related threats