CVE-2026-94160: WordPress ThemeStek Extras for LabtechCO Theme plugin <= 8.4 - Reflected Cross Site Scripting (XSS) vulnerability
Published Oct 10, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeStek ThemeStek Extras for LabtechCO Theme themestek-labtechco-extras allows Reflected XSS.This issue affects ThemeStek Extras for LabtechCO Theme: from n/a through 8.4.
Affected Software
1 affected component
ThemeStek Extras for LabtechCO Theme<=8.4
Event History
Oct 10, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated WordPress account?
No. The supplied vector indicates no privileges are required, though exploitation requires user interaction.
2
Can the issue be exploited remotely?
Yes. The attack vector is network-based and the attack complexity is rated low.
3
What is the expected security impact if exploitation succeeds?
The provided vector rates confidentiality, integrity, and availability impact as low, with scope changed.
4
Which deployments should be considered affected?
Installations using ThemeStek Extras for LabtechCO Theme are affected through version 8.4. The provided data does not specify a lower affected version bound.