CVE-2026-94059: WordPress Ogency theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Ogency ogency allows Reflected XSS.This issue affects Ogency: from n/a through 1.0.0.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack is network-accessible, requires no privileges, and has low attack complexity. It does require user interaction, meaning a victim must be induced to visit or interact with a crafted request or page.
Who is exposed?
Sites using the Bracketweb Ogency WordPress theme are affected through version 1.0.0. The issue is reflected XSS, so exposure depends on users being able to reach attacker-controlled input that is reflected in a page response.
What impact could exploitation have?
Successful exploitation can affect confidentiality, integrity, and availability at low impact levels. Because the scope is changed, the injected script may operate in the security context of the affected site and target users who interact with the malicious content.