CVE-2026-93951: WordPress Zeinet theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Zeinet zeinet allows Reflected XSS.This issue affects Zeinet: from n/a through 1.0.0.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vector is network-accessible and requires no privileges, but exploitation requires user interaction. An attacker would need to induce a user to visit or interact with a crafted request that triggers the reflected XSS.
What impact can successful exploitation have?
The supplied severity vector indicates low confidentiality, integrity, and availability impact, with scope changed. Successful XSS may allow attacker-controlled script to execute in a victim's browser within the affected site's context.
Which Zeinet versions are affected?
Zeinet versions through 1.0.0 are identified as affected. No fixed version is provided in the available data.