Junglewise Threat Intelligence

CVE-2026-78289: CozyStay theme unauthenticated cross-site scripting

CVE-2026-78289 · Severity: high · CVSS 7.1 · Published 2026-08-27

Executive brief

CozyStay is a WordPress theme used by website owners to design and manage their sites. This vulnerability allows attackers to inject malicious scripts into web pages viewed by site visitors, potentially stealing their personal data, session tokens, or account credentials. The attack requires no prior authentication and can be exploited through crafted links or pages that victims visit.

Technical details

CozyStay theme versions 1.10.0 and earlier contain a reflected or stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript code. The vulnerability exists in an unspecified input parameter that is not properly sanitized before being reflected to users. An attacker can craft a malicious URL or page containing JavaScript payload; when a victim visits the link or page, the script executes in their browser context, potentially stealing cookies, session tokens, or performing actions on their behalf. The vulnerability is patched in version 1.10.1 or later.

Affected products

  • LoftOcean CozyStay <= 1.10.0

Timeline

  • 2026-08-25: disclosed
  • 2026-08-27: advisory
  • 2026: patched: Fix available in version 1.10.1

References