VYPR
High severity7.1NVD Advisory· Published Mar 5, 2026· Updated Apr 22, 2026

CVE-2026-28075

CVE-2026-28075

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in p-themes Porto porto allows Reflected XSS.This issue affects Porto: from n/a through <= 7.6.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in p-themes Porto WordPress theme up to v7.6.2 allows script injection via improper input neutralization.

What the vulnerability is

CVE-2026-28075 is a reflected cross-site scripting (XSS) vulnerability in the Porto WordPress theme by p-themes. The software fails to properly neutralize user input during web page generation, allowing an attacker to inject arbitrary HTML or JavaScript into the response. This issue affects all versions from n/a through 7.6.2 [1].

### How it's exploited To exploit the flaw, an attacker must trick a privileged user—such as an administrator—into interacting with a crafted link, form, or other web element. The attack is reflected, meaning the malicious payload is delivered via a request and executed immediately in the victim's browser session. No direct authentication is required from the attacker, but successful exploitation depends on user interaction [1].

Impact

If exploited, the vulnerability enables an attacker to inject malicious scripts that can perform actions like redirecting visitors, displaying advertisements, or other HTML modifications. This can result in a compromise of the affected site's integrity and user experience, and could be leveraged in mass-exploit campaigns against thousands of websites [1].

Mitigation

Users should immediately update the Porto theme to a version newer than 7.6.2 as soon as an official patch is released. In the interim, Patchstack has issued a mitigation rule to block attacks; site owners unable to update should consult their hosting provider or web developer for assistance [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.