CVE-2026-78532: WordPress LMS theme <= 8.3 - Cross Site Scripting (XSS) vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in LMS <= 8.3 versions.
Affected Software
1 affected component
WordPress LMS theme<=8.3
Event History
Oct 10, 2026
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an attacker to have an account?
No. The vulnerability is described as unauthenticated, so an attacker does not need prior authentication.
2
Is user interaction required for exploitation?
Yes. The CVSS vector indicates that user interaction is required.
3
What is the expected impact if exploitation succeeds?
The CVSS metrics indicate low impacts to confidentiality, integrity, and availability. The scope metric is changed.