AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-28154

HIGH · CVSS 7.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability in the Samex and M.Anh WooCommerce WordPress themes allows for reflected cross-site scripting (XSS) due to improper input neutralization during web page generation. This could enable attackers to execute arbitrary scripts in the context of users' browsers, potentially leading to data theft or session hijacking. WordPress site administrators using these themes should prioritize patching or updating to mitigate the risk.

CVE
CVE-2026-28154
Severity
HIGH
CVSS
7.1
EPSS
0.19%
WordPress

Original NVD Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7.