Junglewise Threat Intelligence

CVE-2026-65522: pixelacehq Manual Theme contributor XSS

CVE-2026-65522 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Technologies: Pixelace Manual. Vendors: Pixelace.

Executive brief

The Manual theme for WordPress, which is used to build documentation and knowledge base websites, contains a security flaw that allows users with 'Contributor' level access to inject malicious scripts. If a site administrator or visitor views a page containing these scripts, the attacker could potentially hijack sessions, redirect users to malicious websites, or deface the site. This vulnerability is particularly concerning for organizations using the theme to host internal or external help centers where multiple staff members have content creation permissions.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the pixelacehq Manual - Documentation, Knowledge Base & Education WordPress Theme through version 7.5.4. The flaw is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and stems from insufficient input sanitization and output encoding of user-supplied data. An attacker with Contributor-level privileges can inject arbitrary JavaScript payloads that execute in the context of a victim's browser (typically an administrator) when they view the affected content. As of the advisory date, no official patch has been released.

Affected products

  • pixelacehq Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4

Timeline

  • 2026-06-23: disclosed: Reported by ed32.dll
  • 2026-07-22: advisory: Patchstack published advisory
  • 2026-07-23: advisory: NVD published CVE-2026-65522

References

Related threats