This issue affects Nyla: from n/a through 1.7.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 26 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spabrice
Spabrice nyla Wordpress Wordpress wordpress |
|
| Vendors & Products |
Spabrice
Spabrice nyla Wordpress Wordpress wordpress |
Tue, 26 May 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a through 1.7. | |
| Title | WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-05-26T10:47:43.756Z
Reserved: 2026-04-07T10:57:43.491Z
Link: CVE-2026-39642
Updated: 2026-05-26T10:47:39.226Z
Status : Deferred
Published: 2026-05-26T09:16:20.487
Modified: 2026-06-17T10:42:26.323
Link: CVE-2026-39642
No data.
OpenCVE Enrichment
Updated: 2026-05-26T12:59:38Z