SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85302

MEDIUM · CVSS 6.5 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

WPKoi Templates for Elementor versions up to 3.7.2 are vulnerable to a DOM-based cross-site scripting (XSS) flaw due to improper input neutralization during web page generation. This vulnerability could allow attackers to execute arbitrary scripts in the context of the user's browser, potentially compromising user data and session integrity. WordPress site administrators using affected WPKoi themes should prioritize patching this issue to mitigate the risk of exploitation.

CVE
CVE-2026-85302
Severity
MEDIUM
CVSS
6.5
EPSS
0.13%
WordPress

Original NVD Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2.