CVE-2026-94060: WordPress Voldor theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Voldor voldor allows Reflected XSS.This issue affects Voldor: from n/a through 1.0.0.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack vector is network-based and requires no attacker privileges or prior authentication. However, exploitation requires user interaction, meaning a victim must be induced to access attacker-controlled input or a crafted request.
Which Voldor versions are affected?
The issue affects Bracketweb Voldor through version 1.0.0. The available data does not identify a fixed version.
What is the likely impact if exploitation succeeds?
The vulnerability is a reflected XSS issue with low impacts to confidentiality, integrity, and availability, and its scope can extend beyond the vulnerable component. Successful exploitation could allow script execution in the context of a victim's browser.