CVE-2026-94063: WordPress Education Center theme <= 3.6.12 - Reflected Cross Site Scripting (XSS) vulnerability
Published Oct 9, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Education Center education allows Reflected XSS.This issue affects Education Center: from n/a through 3.6.12.
Affected Software
1 affected component
ThemeREX Education Center<=3.6.12
Event History
Oct 9, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an account or direct access to the site to exploit this issue?
No privileges are required, and the attack vector is network-based. Exploitation does require user interaction.
2
What is the potential impact if exploitation succeeds?
The reported impact includes low-level effects on confidentiality, integrity, and availability, with scope changed. This indicates the XSS may affect a security authority beyond the vulnerable component.
3
Which Education Center versions are identified as affected?
The issue is reported to affect Education Center through version 3.6.12. The provided data does not identify a fixed version.