Junglewise Threat Intelligence

CVE-2026-81281: Graphene WordPress Theme cross-site scripting in subscriber area

CVE-2026-81281 · Severity: medium · CVSS 6.5 · Published 2026-09-03

Executive brief

Graphene is a popular WordPress theme used to customize website appearance and functionality. A cross-site scripting (XSS) vulnerability in versions 2.9.4 and earlier allows attackers to inject malicious code into the subscriber area, potentially enabling account hijacking or theft of visitor data. Exploitation requires a subscriber-level user to interact with a crafted link or form, but once triggered, can affect all site visitors who browse the compromised page.

Technical details

This is a reflected or stored cross-site scripting (XSS) vulnerability in the Graphene WordPress theme affecting versions through 2.9.4. The vulnerability resides in a subscriber-accessible component and requires user interaction—such as clicking a malicious link or submitting a crafted form—for successful exploitation. An attacker can inject arbitrary JavaScript code that executes in the context of the affected website, allowing credential theft, session hijacking, or redirection to phishing pages. The vulnerability has been patched in version 2.9.6; affected users should update immediately.

Affected products

  • Graphene Graphene <= 2.9.4

Timeline

  • 2026-09-03: disclosed: Published on NVD
  • 2026: patched: Fixed in version 2.9.6

References