Junglewise Threat Intelligence

CVE-2026-66612: Aora Theme unauthenticated cross-site scripting

CVE-2026-66612 · Severity: high · CVSS 7.1 · Published 2026-08-20

Executive brief

Aora is a WordPress theme used for website design and presentation. The theme contains an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into affected websites. Successful exploitation could lead to theft of visitor data, account hijacking, or compromise of website functionality without requiring the attacker to authenticate.

Technical details

This is a stored or reflected cross-site scripting (XSS) vulnerability in the Aora WordPress theme versions 1.3.19 and earlier. The vulnerability is unauthenticated, meaning no login is required to exploit it. Exploitation requires user interaction—a visitor or administrator must click a malicious link or visit a crafted page to trigger the attack. Once executed, the injected scripts execute in the victim's browser with their privileges, allowing credential theft, session hijacking, or malware delivery. The vulnerability has been patched in version 1.3.20 and later.

Affected products

  • Aora Aora 1.3.19 and earlier

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: patched in version 1.3.20

References