VYPR
High severity7.1NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026

CVE-2026-24943

CVE-2026-24943

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference grandconference allows Reflected XSS.This issue affects Grand Conference: from n/a through <= 5.3.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in Grand Conference WordPress theme allows attackers to inject malicious scripts via crafted requests, affecting versions up to 5.3.4.

The Grand Conference WordPress theme by ThemeGoods is vulnerable to a reflected cross-site scripting (XSS) attack due to improper neutralization of user-supplied input during web page generation. This flaw affects all versions up to and including 5.3.4, and has been assigned a CVSS v3 score of 7.1 (High) [1].

Exploitation requires user interaction, such as clicking a specially crafted link or visiting a maliciously prepared page. An attacker does not need authentication to deliver the payload, but the victim must perform an action for the script to execute. This makes the vulnerability suitable for mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity [1].

Successful exploitation allows an attacker to inject arbitrary HTML and JavaScript into the victim's browser. This can be used to perform redirects, display advertisements, steal session cookies, or deface the website. The injected script executes in the context of the vulnerable site, potentially compromising the integrity and confidentiality of user data [1].

The vulnerability is patched in version 5.3.5 of the Grand Conference theme. Users are strongly advised to update immediately. If updating is not possible, applying a virtual patch or mitigation rule, such as those provided by Patchstack, can block attacks until the update is applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.