CVE-2026-32449: WordPress Themify Event Post plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability
Published Mar 13, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Event Post themify-event-post allows Stored XSS.This issue affects Themify Event Post: from n/a through <= 1.3.4.
Affected Software
1 affected component
Themify Themify Event Post<=1.3.4
Event History
Mar 13, 2026
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-32449?
CVE-2026-32449 has been classified as a medium severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2026-32449?
To fix CVE-2026-32449, update the Themify Event Post plugin to version 1.3.5 or later.
3
What type of vulnerability is CVE-2026-32449?
CVE-2026-32449 is classified as a Stored Cross Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-32449?
CVE-2026-32449 affects users of the Themify Event Post plugin versions 1.3.4 and below.
5
What can an attacker do with CVE-2026-32449?
An attacker can exploit CVE-2026-32449 to execute malicious scripts in the context of a user's browser.