Junglewise Threat Intelligence

CVE-2026-57684: tranmautritam TheFox contributor XSS

CVE-2026-57684 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Executive brief

TheFox, a popular WordPress theme, contains a security vulnerability that allows users with contributor-level access to inject malicious scripts into the website. If an administrator or site visitor views the affected content, these scripts could execute, potentially leading to unauthorized actions, website redirects, or the theft of sensitive session information. This risk is particularly relevant for sites that allow multiple users to contribute content.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the TheFox WordPress theme through version 3.9.70 due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Contributor' level privileges to inject arbitrary web scripts. Successful exploitation requires a victim (such as an administrator) to interact with the malicious content or visit a crafted page. This can result in the execution of scripts in the context of the victim's browser, enabling session hijacking or unauthorized site modifications. As of the advisory date, no official patch has been released.

Affected products

  • tranmautritam TheFox <= 3.9.70

Timeline

  • 2024-09-17: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-06-29: advisory: Early warning and publication by Patchstack
  • 2026-07-02: other: CVE record published to NVD

References

Related threats