Medium severity6.8NVD Advisory· Published Jul 2, 2026· Updated Jul 2, 2026
CVE-2026-10077
CVE-2026-10077
Description
The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML attributes, which are permitted by wp_kses_post(), as markup, allowing users with the Author role to perform Stored Cross-Site Scripting attacks that execute in the browser of any user who views the affected post.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.