CVE-2025-26917: WordPress WP Templata plugin <= 1.0.7 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata wptemplata allows Reflected XSS.This issue affects WP Templata: from n/a through <= 1.0.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26917?
CVE-2025-26917 is classified as a reflected cross-site scripting (XSS) vulnerability that can compromise user data.
How do I fix CVE-2025-26917?
To fix CVE-2025-26917, update HasThemes WP Templata to a version later than 1.0.7.
What is the impact of CVE-2025-26917 on my website?
CVE-2025-26917 allows an attacker to execute arbitrary JavaScript in the context of the user's browser, potentially leading to data theft or session hijacking.
Which versions of HasThemes WP Templata are affected by CVE-2025-26917?
CVE-2025-26917 affects all versions of HasThemes WP Templata up to and including 1.0.7.
Who is the vendor responsible for CVE-2025-26917?
The vendor responsible for CVE-2025-26917 is HasThemes, which develops the WP Templata plugin.