-
AuthorPosts
-
January 22, 2026 at 8:54 pm #1494195
WordFence Warns
Enfold: Cross Site Scripting (XSS) vulnerability discoveredWe have 20+ sites using Enfold and dread having to change themes.
January 23, 2026 at 6:37 am #1494207Hey Jody,
Thank you for hte inquiry.
This has been fixed in the latest version of the theme (7.1.3). Please make sure to upgrade to the latest version.
Patchstack team XSS vulnerability report: column and cell link fixed
Best regards,
IsmaelJanuary 23, 2026 at 8:01 am #1494212Hi Ismael,
Sorry, but you have a current new security vulnerability that was published three days ago on Patchstack! And not the vulnerability that was fixed with 7.1.3 in October 2025!
https://patchstack.com/database/wordpress/theme/enfold/vulnerability/wordpress-enfold-theme-7-1-3-cross-site-scripting-xss-vulnerabilitySo please check and fix it quickly and deliver an appropriate version.
January 23, 2026 at 2:17 pm #1494228Solutions
This security issue has a low severity impact and is unlikely to be exploited.maybe it is not so urgent ;)
____________________
Perhaps it’s time to introduce a nonce solution for all Enfold scripts?
(for my own i have written a small plugin that will bring to every script/inline-script a nonce-key; and my csp directive says:
script-src ‘nonce-key==’ ‘strict-dynamic’ ) that is the best against XSS – and check f.e. on: https://securityheaders.com/?q=https%3A%2F%2Fwebers-testseite.de&followRedirects=on )January 28, 2026 at 11:06 pm #1494458AgenturWP is correct. You have a new issue.
January 28, 2026 at 11:14 pm #1494459I also reported it on Themeforest – looking for when 7.1.4 will be available.
January 29, 2026 at 3:51 am #1494464Also looking forward for a patch.
January 29, 2026 at 5:51 am #1494481Hi,
A patch will be included in the next version (7.1.14) and will be released soon. Thank you for your patience.
Best regards,
IsmaelFebruary 9, 2026 at 11:46 am #1494883Hey Ismael,
When will the update be available? My clients are worried.
tnx
CFebruary 9, 2026 at 11:55 am #1494884I am also worried (for my clients)
February 9, 2026 at 12:25 pm #1494886Hi Ismael
+1
When will the next version be released? Thanks. -
AuthorPosts
- You must be logged in to reply to this topic.
