CVE-2026-25351: WordPress MyMedi theme < 1.7.7 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 25, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup MyMedi mymedi allows Reflected XSS.This issue affects MyMedi: from n/a through < 1.7.7.
Affected Software
1 affected component
Skygroup MyMedi (WordPress theme)<1.7.7
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25351?
CVE-2026-25351 has a medium severity rating due to its reflected cross-site scripting risk.
2
How do I fix CVE-2026-25351?
To fix CVE-2026-25351, update the MyMedi theme to version 1.7.7 or later.
3
What does CVE-2026-25351 affect?
CVE-2026-25351 affects versions of the MyMedi theme from n/a to below 1.7.7.
4
What type of vulnerability is CVE-2026-25351?
CVE-2026-25351 is a reflected cross-site scripting (XSS) vulnerability.
5
Who is the vendor for the CVE-2026-25351 affected product?
The vendor for the affected product is Skygroup.