CVE-2026-27358: WordPress Architecturer theme < 3.9.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Architecturer allows Reflected XSS.This issue affects Architecturer: from n/a before 3.9.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Architecturer architecturer allows Reflected XSS.This issue affects Architecturer: from n/a through < 3.9.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27358?
CVE-2026-27358 has a medium severity rating due to the potential for reflected XSS attacks.
How do I fix CVE-2026-27358?
To fix CVE-2026-27358, update the ThemeGoods Architecturer theme to version 3.9.5 or later.
What type of vulnerability is CVE-2026-27358?
CVE-2026-27358 is a Cross Site Scripting (XSS) vulnerability affecting the Architecturer theme.
Who is affected by CVE-2026-27358?
Users of ThemeGoods Architecturer theme versions prior to 3.9.5 are affected by CVE-2026-27358.
What causes the vulnerability in CVE-2026-27358?
The vulnerability in CVE-2026-27358 is caused by improper neutralization of input during web page generation.