Junglewise Threat Intelligence

CVE-2026-57618: Themeisle Neve PRO Contributor Cross Site Scripting

CVE-2026-57618 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Vendors: Themeisle.

Executive brief

Neve PRO is a premium WordPress theme used for website design and customization. A security vulnerability in versions 3.1.2 and earlier allows users with 'Contributor' level access to inject malicious scripts into the website. If an administrator views the affected content, these scripts could lead to unauthorized actions, website defacement, or the redirection of visitors to malicious sites.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Neve PRO theme for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Contributor' privileges to inject arbitrary JavaScript into the site. Exploitation requires a victim (typically an administrator) to interact with the malicious content or perform a specific action, such as visiting a crafted page. This can lead to session hijacking or unauthorized administrative actions via the victim's browser. The issue is resolved in version 3.1.3.

Affected products

  • Themeisle Neve PRO <= 3.1.2

Timeline

  • 2025-10-26: disclosed: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-06-25: advisory: Published by Patchstack
  • 2026-06-25: patched: Fixed in version 3.1.3

References