CVE-2026-81281: WordPress Graphene theme <= 2.9.4 - Cross Site Scripting (XSS) vulnerability
Published Sep 3, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
Affected Software
1 affected component
WordPress Graphene theme<=2.9.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Graphene Themeto a version that resolves this vulnerability.Fixed in 2.9.6
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Subscriber-level access to a WordPress site using the affected Graphene theme. Exploitation also requires user interaction, as indicated by the UI:R vector.
2
What is the potential impact?
Successful exploitation may allow cross-site scripting in a victim's browser. The published vector indicates low impact to confidentiality, integrity, and availability, with scope changed.