ZeroHour

CVE-2026-81291

large

Unauthenticated XSS in Uncode WordPress Theme (≤ 2.12.7)

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-81291 is an unauthenticated cross-site scripting (XSS) flaw in the Uncode WordPress theme, affecting all versions up to and including 2.12.7. Because it requires no privileges and has low attack complexity, an unauthenticated attacker can craft a request or link that, when viewed by a victim (user interaction required per the CVSS vector), executes attacker-controlled JavaScript in the context of the affected site. Successful exploitation could allow session or cookie theft, forced redirects, phishing overlays, or unwanted actions performed in the victim's browser, including if the victim is a logged-in site administrator. Any WordPress site running the Uncode theme at version 2.12.7 or earlier is affected. Exploitation status is calm: there is no public proof of concept, the flaw is not in CISA KEV, and EPSS assigns only about a 0.2% probability of exploitation within 30 days (8th percentile), so no exploitation is currently known.

What to do: Update the Uncode theme to the latest available release (any version above 2.12.7); do not remain on 2.12.7 or older. If you cannot patch immediately, virtual-patch with a WAF rule blocking unauthenticated script injection targeting theme endpoints and review the site for signs of abuse (unexpected admin users, injected scripts or redirects). Given no public PoC and low EPSS, standard patching timelines are acceptable, but unauthenticated XSS in popular WordPress themes is frequently rediscovered, so treat the update as urgent.

Affected
Undersigned Uncode (WordPress theme)<= 2.12.7
Estimated exposure
largetens of thousands of sites (on the order of 50,000+ commercial licenses sold; currently active affected sites likely lower) — Uncode is a premium ThemeForest theme and Envato publishes cumulative sales (roughly 50k+) rather than active installs, so sales counts are used as a proxy and the true number of live, vulnerable installations is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.