Cross-site Scripting Vulnerability in ThemeREX Addons by ThemeREX Group
CVE-2026-102798
6.5MEDIUM
What is CVE-2026-102798?
An improper neutralization of input during web page generation vulnerability has been identified in ThemeREX Addons, which allows attackers to conduct stored cross-site scripting (XSS) attacks. This flaw affects all versions of the plugin up to 2.46.0, potentially enabling unauthorized users to execute arbitrary scripts in the context of an affected user's browser session. Users are strongly advised to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
ThemeREX Addons 0 <= 2.46.0