CVE-2026-32333: WordPress Mayosis Core plugin <= 5.4.7 - Reflected Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Mayosis Core pluginto a version that resolves this vulnerability.Fixed in 5.4.7
Event History
Frequently Asked Questions
Which deployments are exposed?
Sites using WordPress Mayosis Core version 5.4.7 or earlier are affected. The issue is unauthenticated, so an attacker does not need an account on the target site.
What does an attacker need to exploit this issue?
The CVSS vector indicates network-reachable exploitation with low attack complexity and required user interaction. A victim must interact with attacker-supplied content or a crafted request for the reflected XSS to execute.
What can be done while a patch is unavailable?
The provided information identifies affected versions through 5.4.7 but does not specify a fixed version or workaround. If patching cannot occur immediately, assess exposure to attacker-controlled links or requests that could be opened by site users or administrators.