Junglewise Threat Intelligence

CVE-2026-84815: Kriesi Enfold reflected cross-site scripting

CVE-2026-84815 · Severity: medium · CVSS 5.8 · Published 2026-09-03

Executive brief

Enfold is a popular WordPress theme used by thousands of websites. The theme contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into affected sites. Exploited through malicious links or pages, this can lead to visitor data theft, account hijacking, or widespread attacks against multiple websites simultaneously.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability in Kriesi Enfold through version 8.0 arising from improper neutralization of user input during web page generation. The vulnerability is network-accessible and requires user interaction (e.g., clicking a malicious link or visiting a crafted page); no authentication is required. An unauthenticated attacker can inject arbitrary JavaScript into pages viewed by victims, allowing credential theft, session hijacking, or malware distribution. The vulnerability was patched in version 8.1.

Affected products

  • Kriesi Enfold through 8.0

Timeline

  • 2026-08-26: disclosed: Reported by Rafie Muhammad
  • 2026-09-03: advisory: Published by Patchstack
  • 2026-09-03: patched: Patched in version 8.1

References

Related threats