WORDFENCE-f88eaf82-e5de-43e2-b998-4a6d33be65ac
medium
📛 Threat Title
Parallelus Unite, Interscet, Traject, & Salutation < 2.0 - Reflected Cross-Site Scripting
Description
The Parallelus Unite, Intersect, Traject, & Salutation Premium WordPress Themes for WordPress are vulnerable to Reflected Cross-Site Scripting in versions up to 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser. Affected software — theme: Parallelus Intersect (affected: [*, 2.0)); theme: Parallelus Unite (affected: [*, 2.0)); theme: Salutation Responsive WordPress Theme (affected: [*, 2.0)); theme: Parallelus Traject (affected: [*, 2.0)). CVSS 6.1 (Medium) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (4)
-
Wordfence remediation: Parallelus IntersectWordfence
Update to version 2.0, or a newer patched version
-
Wordfence remediation: Parallelus UniteWordfence
Update to version 2.0, or a newer patched version
-
Wordfence remediation: Salutation Responsive WordPress ThemeWordfence
Update to version 2.0, or a newer patched version
-
Wordfence remediation: Parallelus TrajectWordfence
Update to version 2.0, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.