CVE-2026-25356: WordPress Yobazar theme < 1.6.7 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 25, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Yobazar yobazar allows Reflected XSS.This issue affects Yobazar: from n/a through < 1.6.7.
Affected Software
1 affected component
Skygroup Yobazar WordPress theme<1.6.7
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25356?
CVE-2026-25356 has been assessed with a medium severity due to its potential for exploitation via reflected cross-site scripting.
2
How do I fix CVE-2026-25356?
To fix CVE-2026-25356, users should update the Yobazar theme to version 1.6.7 or later.
3
What type of vulnerability is identified in CVE-2026-25356?
CVE-2026-25356 identifies a reflected cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-25356?
Users of the Skygroup Yobazar WordPress theme prior to version 1.6.7 are affected by CVE-2026-25356.
5
What are the potential impacts of CVE-2026-25356?
The potential impacts of CVE-2026-25356 include unauthorized access to sensitive user information and session hijacking.