CVE-2026-39642: WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability
Published May 26, 2026
·Updated
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection.
This issue affects Nyla: from n/a through 1.7.
Affected Software
1 affected component
SpabRice Nyla (WordPress theme)<=1.7
Event History
May 26, 2026
CVE Published
via MITRE·07:51 AM
Data Sourced
via MITRE·07:51 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39642?
The severity of CVE-2026-39642 is medium with a score of 5.3.
2
How do I fix CVE-2026-39642?
To fix CVE-2026-39642, update the SpabRice Nyla theme to version 1.8 or higher.
3
What type of vulnerability is CVE-2026-39642?
CVE-2026-39642 is an arbitrary shortcode execution vulnerability related to improper neutralization of script-related HTML tags.
4
Which versions of the SpabRice Nyla theme are affected by CVE-2026-39642?
CVE-2026-39642 affects SpabRice Nyla theme versions up to and including 1.7.
5
What impact does CVE-2026-39642 have on a WordPress site?
CVE-2026-39642 can lead to code injection through arbitrary shortcode execution, potentially allowing attackers to execute malicious scripts.