CVE-2026-28073: WordPress WP eMember theme <= v10.2.2 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember allows Reflected XSS.This issue affects WP eMember: from n/a through v10.2.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ WP eMember wp-eMember allows Reflected XSS.This issue affects WP eMember: from n/a through <= v10.2.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28073?
CVE-2026-28073 is classified as a medium severity reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2026-28073?
To fix CVE-2026-28073, you need to update the WP eMember plugin to the latest version beyond 10.2.2.
Who is affected by CVE-2026-28073?
CVE-2026-28073 affects users of the WP eMember theme versions from an unknown version up to 10.2.2.
What type of vulnerability is CVE-2026-28073?
CVE-2026-28073 is a reflected cross-site scripting (XSS) vulnerability.
What can attackers do with CVE-2026-28073?
Attackers can exploit CVE-2026-28073 to inject malicious scripts into web pages, potentially compromising user data.