Cross-site Scripting Vulnerability in ThemeREX Addons by ThemeREX Group
CVE-2026-102798

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 October 2026

What is CVE-2026-102798?

An improper neutralization of input during web page generation vulnerability has been identified in ThemeREX Addons, which allows attackers to conduct stored cross-site scripting (XSS) attacks. This flaw affects all versions of the plugin up to 2.46.0, potentially enabling unauthorized users to execute arbitrary scripts in the context of an affected user's browser session. Users are strongly advised to update to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

ThemeREX Addons 0 <= 2.46.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nh4tvd | Patchstack Bug Bounty Program
.