CVE-2026-57806: WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.3.9 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in drfuri Martfury - WooCommerce Marketplace WordPress Theme martfury allows Reflected XSS.This issue affects Martfury - WooCommerce Marketplace WordPress Theme: from n/a through 3.3.9.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker can reach the vulnerable functionality over the network without authentication, but exploitation requires user interaction. A victim must be induced to access attacker-controlled input that is reflected into a web page.
What versions should be considered affected?
Martfury - WooCommerce Marketplace WordPress Theme versions through 3.3.9 are affected. The available information does not identify a fixed version.
What is the likely impact if exploitation succeeds?
Successful reflected XSS can execute attacker-supplied script in the affected site's context. The reported impact includes low confidentiality, integrity, and availability effects, and the scope may extend beyond the vulnerable component.