CVE-2026-28154: WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS.
This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28154?
The severity of CVE-2026-28154 is rated as high with a score of 7.1.
What does CVE-2026-28154 affect?
CVE-2026-28154 affects the Samex and M.Anh WordPress themes, leading to a Cross Site Scripting (XSS) vulnerability.
How do I fix CVE-2026-28154?
To fix CVE-2026-28154, update the affected Samex and M.Anh themes to the latest patched version.
What type of vulnerability is CVE-2026-28154?
CVE-2026-28154 is classified as a Cross Site Scripting (XSS) vulnerability.
What impact does CVE-2026-28154 have on users?
CVE-2026-28154 allows for reflected XSS attacks, potentially exposing users to malicious scripts.