Junglewise Threat Intelligence

CVE-2026-65511: pixelacehq Manual Theme Unauthenticated XSS

CVE-2026-65511 · Severity: high · CVSS 7.1 · Published 2026-07-23

Technologies: Pixelace Manual. Vendors: Pixelace.

Executive brief

The Manual theme for WordPress, used for creating documentation and knowledge base websites, contains a security flaw that allows attackers to inject malicious scripts. If a site administrator or visitor clicks on a specially crafted link, the attacker can execute code in their browser. This could lead to unauthorized actions, theft of session information, or the display of fraudulent content on the site.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Manual - Documentation, Knowledge Base & Education WordPress theme (versions 7.5.4 and below) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions if the victim is an authenticated administrator. As of the advisory date, no official patch has been released.

Affected products

  • pixelacehq Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4

Timeline

  • 2026-06-22: disclosed: Vulnerability reported by researcher ed32.dll
  • 2026-07-23: advisory: Advisory published by Patchstack and NVD

References

Related threats