CVE-2026-27086: WordPress WoodMart theme < 8.3.8 - Cross Site Scripting (XSS) vulnerability
Published Sep 4, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS.
This issue affects WoodMart: from n/a before 8.3.8.
Affected Software
1 affected component
WordPress WoodMart theme<8.3.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WoodMart Themeto a version that resolves this vulnerability.Fixed in 8.3.8
Event History
Sep 4, 2026
CVE Published
via MITRE·09:22 AM
Data Sourced
via MITRE·09:22 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
WoodMart versions before 8.3.8 are affected. The available data does not identify a lower bound for affected versions.
2
What does an attacker need to exploit this issue?
The CVSS vector indicates network access, low privileges, and user interaction are required. Exploitation may have low impact on confidentiality, integrity, and availability, with scope changed.