CVE-2026-81291
largeUnauthenticated XSS in Uncode WordPress Theme (≤ 2.12.7)
CVE-2026-81291 is an unauthenticated cross-site scripting (XSS) flaw in the Uncode WordPress theme, affecting all versions up to and including 2.12.7. Because it requires no privileges and has low attack complexity, an unauthenticated attacker can craft a request or link that, when viewed by a victim (user interaction required per the CVSS vector), executes attacker-controlled JavaScript in the context of the affected site. Successful exploitation could allow session or cookie theft, forced redirects, phishing overlays, or unwanted actions performed in the victim's browser, including if the victim is a logged-in site administrator. Any WordPress site running the Uncode theme at version 2.12.7 or earlier is affected. Exploitation status is calm: there is no public proof of concept, the flaw is not in CISA KEV, and EPSS assigns only about a 0.2% probability of exploitation within 30 days (8th percentile), so no exploitation is currently known.
What to do: Update the Uncode theme to the latest available release (any version above 2.12.7); do not remain on 2.12.7 or older. If you cannot patch immediately, virtual-patch with a WAF rule blocking unauthenticated script injection targeting theme endpoints and review the site for signs of abuse (unexpected admin users, injected scripts or redirects). Given no public PoC and low EPSS, standard patching timelines are acceptable, but unauthenticated XSS in popular WordPress themes is frequently rediscovered, so treat the update as urgent.
| Undersigned Uncode (WordPress theme) | <= 2.12.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.