CVE-2026-27367: WordPress Musico theme < 3.4.5 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Musico allows Reflected XSS.This issue affects Musico: from n/a before 3.4.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Musico musico allows Reflected XSS.This issue affects Musico: from n/a through < 3.4.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27367?
CVE-2026-27367 is considered a medium severity Cross Site Scripting (XSS) vulnerability affecting the Musico theme.
How do I fix CVE-2026-27367?
To fix CVE-2026-27367, you should update the Musico theme to version 3.4.5 or later.
What does CVE-2026-27367 affect?
CVE-2026-27367 affects versions of the WordPress Musico theme prior to 3.4.5.
What type of vulnerability is CVE-2026-27367?
CVE-2026-27367 is a Cross Site Scripting (XSS) vulnerability that allows for Reflected XSS.
Who is the vendor of the affected software for CVE-2026-27367?
The vendor of the affected software for CVE-2026-27367 is ThemeGoods.