← WordPress Vulnerabilities
WordPress security by component

thefox

thefox is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 02, 2026; the highest published CVSS base score is 7.1.

Theme slug: thefox

CVE-2026-57684: TheFox: Cross-site scripting

TheFox is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.9.70.

PublishedJul 02, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for thefox
Safe version
Jul 02, 2026 CVE-2026-57684
TheFox: Cross-site scripting
TheFox is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.9.70.
See mitigation notes
CVE6.5
NVDPending
Jul 02, 2026 CVE-2026-27430
TheFox: Cross-site scripting
TheFox is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.9.76.
See mitigation notes
CVE7.1
NVDPending