← WordPress Vulnerabilities
WordPress security by component

urna

urna is a WordPress theme with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 24, 2026; the highest published CVSS base score is 8.1.

Theme slug: urna

CVE-2026-66610: Urna permits unauthenticated cross-site scripting

Urna through 2.6.2 accepts unauthenticated attacker-controlled input that reaches browser output without adequate neutralization. A victim must visit or interact with the affected content for script to execute in the site's origin, allowing access to data and actions available to that browser session.

PublishedAug 24, 2026
Known safe version2.6.3
Published vulnerabilities for urna
Safe version
Aug 24, 2026 CVE-2026-66610
Urna permits unauthenticated cross-site scripting
Urna through 2.6.2 accepts unauthenticated attacker-controlled input that reaches browser output without adequate neutralization. A victim must visit or interact with the affected content for script to execute in the site's origin, allowing access to data and actions available to that browser session.
2.6.3
CVE7.1
NVDPending
Feb 20, 2026 CVE-2025-67982
Urna: Filesystem traversal
Urna is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVDPending
Dec 09, 2025 CVE-2025-67528
Urna: Filesystem traversal
Urna is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Aug 14, 2025 CVE-2025-54689
Urna: Filesystem traversal
Urna is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVDPending