CVE-2026-25349: WordPress Loobek theme < 1.5.2 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 25, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Loobek loobek allows Reflected XSS.This issue affects Loobek: from n/a through < 1.5.2.
Affected Software
1 affected component
Skygroup Loobek<1.5.2
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25349?
CVE-2026-25349 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2026-25349?
To fix CVE-2026-25349, update the Skygroup Loobek theme to version 1.5.2 or later.
3
What impacts does CVE-2026-25349 have on my website?
CVE-2026-25349 can allow attackers to execute malicious scripts in the context of the user's browser, potentially compromising user data.
4
Is CVE-2026-25349 present in all versions of Skygroup Loobek?
CVE-2026-25349 affects all versions of Skygroup Loobek prior to 1.5.2.
5
How can I determine if my site is vulnerable to CVE-2026-25349?
You can determine if your site is vulnerable to CVE-2026-25349 by checking if the Skygroup Loobek theme is installed and is below version 1.5.2.