CVE-2026-27352: WordPress Starto theme < 2.2.5 - Cross Site Scripting (XSS) vulnerability
Published Mar 5, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Starto allows Reflected XSS.This issue affects Starto: from n/a before 2.2.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Starto starto allows Reflected XSS.This issue affects Starto: from n/a through < 2.2.5.
— MITRE
Affected Software
1 affected component
ThemeGoods Starto<2.2.5
Remediation
Information
Update the WordPress Starto theme to the latest available version (at least 2.2.5).
Event History
Mar 5, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness