Improper Script Neutralization in SpabRice Nyla Theme
CVE-2026-39642
5.3MEDIUM
What is CVE-2026-39642?
The SpabRice Nyla theme is susceptible to a code injection vulnerability caused by improper neutralization of script-related HTML tags in web pages. This flaw can allow an attacker to exploit the website by injecting malicious scripts, potentially compromising the integrity and security of the site. Users of Nyla must implement immediate action to secure their sites, especially those using versions up to 1.7, to prevent abuse of this vulnerability.
Affected Version(s)
Nyla <= 1.7
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program