CVE-2026-27348: WordPress Photography theme < 7.7.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography allows DOM-Based XSS.This issue affects Photography: from n/a before 7.7.6.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows DOM-Based XSS.This issue affects Photography: from n/a through < 7.7.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27348?
The severity of CVE-2026-27348 is considered moderate due to its potential for Cross Site Scripting (XSS) attacks.
How do I fix CVE-2026-27348?
To fix CVE-2026-27348, update the ThemeGoods Photography theme to version 7.6.2 or later.
What type of vulnerability is CVE-2026-27348?
CVE-2026-27348 is a Cross Site Scripting (XSS) vulnerability caused by improper neutralization of input.
Which versions of ThemeGoods Photography are affected by CVE-2026-27348?
CVE-2026-27348 affects ThemeGoods Photography versions from n/a up to and including 7.6.1.
What can attackers achieve using CVE-2026-27348?
Attackers can exploit CVE-2026-27348 to execute arbitrary JavaScript code in the context of the user's session.