CVE-2026-27332: WordPress Agrofood theme < 1.4.0 - Cross Site Scripting (XSS) vulnerability
Published Mar 5, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Agrofood agrofood allows Reflected XSS.This issue affects Agrofood: from n/a through < 1.4.0.
Affected Software
1 affected component
Skygroup Agrofood (WordPress theme)<1.4.0
Remediation
Information
Update the WordPress Agrofood theme to the latest available version (at least 1.4.0).
Event History
Mar 5, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27332?
CVE-2026-27332 has a high severity due to its potential for reflected XSS attacks.
2
How do I fix CVE-2026-27332?
To fix CVE-2026-27332, update the Agrofood theme to the latest version beyond 1.3.0.
3
What kind of vulnerabilities does CVE-2026-27332 have?
CVE-2026-27332 has a reflected cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-27332?
CVE-2026-27332 affects users of the WordPress Agrofood theme version 1.3.0 and below.
5
Is CVE-2026-27332 an ongoing risk?
Yes, until patching is done or the theme is updated, CVE-2026-27332 remains an ongoing security risk.