Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS.

This issue affects News Theme V8: through 16.06.2026.
Published: 2026-07-28
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The affected theme contains an improper neutralization of input during web page generation, resulting in reflected cross‑site scripting. This flaw allows an attacker to embed malicious scripts that execute in a victim’s browser when a crafted URL is visited, enabling session hijacking, credential theft, or the injection of fraudulent content.

Affected Systems

The vulnerability impacts THEWP Digital Solutions News Theme V8 versions up to 16.06.2026 inclusive. Users running any version before the release of a fixed build are susceptible.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium severity, and the EPSS score of less than 1% implies a low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Reflected XSS attacks typically require a victim to click a malicious link or be tricked into viewing a crafted page, so the threat is operationally limited to the user’s browser. However, because the payload runs with the victim’s privileges, the attack can compromise data confidentiality and integrity.

Generated by OpenCVE AI on August 3, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade News Theme V8 to the latest patched version or a version released after 16.06.2026.
  • Apply proper input validation and output encoding throughout the theme to neutralize injected scripts.
  • Deploy a robust Content Security Policy that blocks inline scripts and unsafe evaluations.

Generated by OpenCVE AI on August 3, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Thewp Digital Solutions
Thewp Digital Solutions news Theme V8
Wordpress
Wordpress wordpress
Vendors & Products Thewp Digital Solutions
Thewp Digital Solutions news Theme V8
Wordpress
Wordpress wordpress

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026.
Title Reflected XSS in theWP's News Theme V8
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Thewp Digital Solutions News Theme V8
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-28T12:43:39.129Z

Reserved: 2026-05-08T12:26:28.236Z

Link: CVE-2026-8167

cve-icon Vulnrichment

Updated: 2026-07-28T12:43:35.513Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T09:16:42.690

Modified: 2026-07-28T16:10:09.517

Link: CVE-2026-8167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')