CVE-2026-94061: WordPress Whistle - Sports Club theme <= 4.2 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designthemes Whistle - Sports Club whistle-sports-club allows Reflected XSS.This issue affects Whistle - Sports Club: from n/a through 4.2.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vector is network-accessible and requires no attacker privileges, but exploitation requires user interaction. An attacker would need to induce a user to visit or interact with a crafted request that triggers the reflected XSS.
Which installations are affected?
Whistle - Sports Club versions through 4.2 are affected. The available data does not identify a fixed version or state whether any particular configuration is required.
What is the likely impact if exploitation succeeds?
Successful exploitation can affect confidentiality, integrity, and availability at low impact levels. Because the scope is changed, the XSS may affect a security context beyond the vulnerable theme component.