CVE-2026-27382: WordPress Metro theme <= 2.13 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 5, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Metro metro allows DOM-Based XSS.This issue affects Metro: from n/a through <= 2.13.
Affected Software
2 affected components
RadiusTheme Metro<=2.13
WordPress Metro<=2.13
Event History
Mar 5, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27382?
CVE-2026-27382 is rated as a medium severity vulnerability due to the potential for reflected cross-site scripting (XSS) exploitation.
2
How do I fix CVE-2026-27382?
To fix CVE-2026-27382, users should update the RadiusTheme Metro theme to version 2.14 or later.
3
Who is affected by CVE-2026-27382?
CVE-2026-27382 affects all users of the WordPress Metro theme versions 2.13 and earlier.
4
What type of vulnerability is CVE-2026-27382?
CVE-2026-27382 is a reflected cross-site scripting (XSS) vulnerability.
5
Where can I find more information about CVE-2026-27382?
More details about CVE-2026-27382 can usually be found in the official security databases or vulnerability repositories.