WordPress security by component
aora
aora is a WordPress theme with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 20, 2026; the highest published CVSS base score is 8.1.
Theme slug:
aoraLatest vulnerability
CVE-2026-66612: Aora permits unauthenticated cross-site scripting
Aora <= 1.3.19 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.
| Safe version |
|
||
|---|---|---|---|
| Aug 20, 2026 |
CVE-2026-66612
Aora permits unauthenticated cross-site scripting
Aora <= 1.3.19 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.
|
1.3.20 |
CVE7.1
NVDPending
|
| Mar 05, 2026 |
CVE-2026-27381
Aora: Filesystem traversal
Aora is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Dec 30, 2025 |
CVE-2025-68985
Aora: Filesystem traversal
Aora is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jun 17, 2025 |
CVE-2025-49260
Aora: Filesystem traversal
Aora is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.1
NVDPending
|