Kutethemes Uminex WordPress Theme Content Injection Vulnerability

Vulnerability

A content injection vulnerability has been identified in the Kutethemes Uminex WordPress theme, specifically in versions through 1.0.9. This vulnerability allows for improper neutralization of script-related HTML tags, leading to basic cross-site scripting (XSS) issues and arbitrary shortcode execution.

Impact

Exploitation of this vulnerability could allow a malicious actor to inject content into pages and posts, potentially including phishing materials.

Remediation

Users are advised to update the Uminex WordPress theme to the latest version. If an update is not possible, consult with your hosting provider or web developer for assistance.

Added: Apr 8, 2026, 10:24 AM
Updated: Apr 8, 2026, 10:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.6
remediation
0.0
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.