Unauthenticated Content Injection Vulnerability in Boutique Theme by Kute
CVE-2026-62098
6.5MEDIUM
What is CVE-2026-62098?
The Boutique theme, developed by Kute, is susceptible to an unauthenticated content injection vulnerability in versions up to 2.3.3. This flaw could allow attackers to inject arbitrary content on websites using this theme, potentially leading to security breaches or unauthorized access. Users are recommended to update to the latest version to mitigate associated risks.
Affected Version(s)
Boutique <= 2.3.3
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program