PT-2026-54610 · WordPress · Yootheme Pro

·

CVE-2026-10077

·

Published

2026-07-02

·

Updated

2026-07-02

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YOOtheme Pro versions prior to 5.0.35
Description The bundled front-end framework fails to prevent certain HTML attributes, which are permitted by the wp kses post() function, from being treated as markup. This allows users with the Author role to execute Stored Cross-Site Scripting (XSS) attacks in the browser of any user who views the affected post.
Recommendations Update YOOtheme Pro to version 5.0.35 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-10077

Affected Products

Yootheme Pro