Junglewise Threat Intelligence

CVE-2026-66610: Urna theme unauthenticated cross site scripting

CVE-2026-66610 · Severity: high · CVSS 7.1 · Published 2026-08-24

Executive brief

Urna is a WordPress theme used to build and design websites. An unauthenticated cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts that can steal visitor data, hijack user accounts, or compromise website functionality without requiring authentication or special privileges.

Technical details

The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in the Urna WordPress theme versions 2.6.2 and earlier. The issue requires user interaction—a victim must click a malicious link or visit a crafted page for exploitation. No authentication is required to craft or deliver the exploit. Successful exploitation allows attackers to execute arbitrary JavaScript in the context of the victim's browser, enabling account hijacking, data theft, or malware distribution. The vulnerability has been patched in version 2.6.3 and later.

Affected products

  • Urna Urna <=2.6.2

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Patched in version 2.6.3

References