Cross-Site Scripting Vulnerability in Vantage Theme for WordPress
CVE-2026-5070
6.4MEDIUM
What is CVE-2026-5070?
The Vantage theme for WordPress is affected by a Stored Cross-Site Scripting vulnerability found in the Gallery block text content. Due to inadequate output escaping in the gallery template, authenticated users, particularly those with contributor-level access and higher, can exploit this flaw to inject arbitrary scripts. These scripts execute when users visit impacted pages, potentially compromising user data and site integrity.
Affected Version(s)
Vantage 0 <= 1.20.32