Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS.

This issue affects WoodMart: from n/a before 8.3.8.
Published: 2026-09-04
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows a DOM-Based XSS flaw. The vulnerability arises when the theme fails to sanitize user‑provided data before injecting it into the page’s DOM. Based on the description of DOM‑based XSS, it is inferred that an attacker could inject arbitrary JavaScript that would execute in the victim’s browser, potentially allowing information disclosure, session hijacking, or other malicious actions.

Affected Systems

The vulnerability affects the Xtemos WoodMart WordPress theme in all releases prior to version 8.3.8. WordPress sites that have not upgraded the theme remain vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EPSS score is not available, so the exploitation probability is unknown. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is via any user input or URL parameters that the WoodMart theme processes without proper sanitization, so any user who can submit data to the site could trigger the XSS attack.

Generated by OpenCVE AI on September 4, 2026 at 10:50 UTC.

Remediation

Vendor Solution

Update the WordPress WoodMart Theme to the latest available version (at least 8.3.8).


OpenCVE Recommended Actions

  • Update the WoodMart theme to version 8.3.8 or later, which removes the vulnerable code and implements proper input sanitization.
  • If a theme upgrade is delayed, disable or sanitize features that allow raw user input to be rendered, such as disabling shortcodes or widgets that output unfiltered HTML.
  • After applying the patch or mitigating configuration changes, perform a security review and test for XSS vulnerabilities, and monitor the site for unexpected scripts or data injection attempts.

Generated by OpenCVE AI on September 4, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Xtemos
Xtemos woodmart
Vendors & Products Wordpress
Wordpress wordpress
Xtemos
Xtemos woodmart

Fri, 04 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: from n/a before 8.3.8.
Title WordPress WoodMart theme < 8.3.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Xtemos Woodmart
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-04T09:22:57.652Z

Reserved: 2026-02-17T13:23:58.964Z

Link: CVE-2026-27086

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T10:17:11.843

Modified: 2026-09-04T10:17:11.843

Link: CVE-2026-27086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T11:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')