← WordPress Vulnerabilities
WordPress security by component

aora

aora is a WordPress theme with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 20, 2026; the highest published CVSS base score is 8.1.

Theme slug: aora

CVE-2026-66612: Aora permits unauthenticated cross-site scripting

Aora <= 1.3.19 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.

PublishedAug 20, 2026
Known safe version1.3.20
Published vulnerabilities for aora
Safe version
Aug 20, 2026 CVE-2026-66612
Aora permits unauthenticated cross-site scripting
Aora <= 1.3.19 allows an unauthenticated attacker to supply script-capable input that reaches browser output without adequate neutralization. The CNA vector requires victim interaction and assigns changed scope with low confidentiality, integrity and availability impact. Script executes in the site's origin when a victim interacts with the affected output.
1.3.20
CVE7.1
NVDPending
Mar 05, 2026 CVE-2026-27381
Aora: Filesystem traversal
Aora is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVDPending
Dec 30, 2025 CVE-2025-68985
Aora: Filesystem traversal
Aora is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Jun 17, 2025 CVE-2025-49260
Aora: Filesystem traversal
Aora is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVDPending