PT-2026-36597 · WordPress · Total
Published
2026-05-02
·
Updated
2026-05-02
·
CVE-2026-5077
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Total theme for WordPress versions prior to 2.2.2
Description
Stored Cross-Site Scripting is possible via post titles due to insufficient output escaping when rendering the
the title() function inside HTML attribute context in the home blog section template. Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages. These scripts execute when a user accesses an injected page, provided the malicious post is published and displayed with a featured image in the Home Page blog section.Recommendations
Update to a version later than 2.2.1.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Total