Junglewise Threat Intelligence

CVE-2026-27086: Xtemos WoodMart DOM-based XSS vulnerability

CVE-2026-27086 · Severity: medium · CVSS 6.5 · Published 2026-09-04

Executive brief

WoodMart is a popular WordPress theme used to create e-commerce storefronts. A DOM-based cross-site scripting (XSS) vulnerability in versions before 8.3.8 allows attackers to inject malicious scripts that can steal visitor data or hijack customer accounts. Exploitation requires user interaction, such as clicking a malicious link or visiting a specially crafted page.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability caused by improper neutralization of user input during web page generation in the WoodMart theme. The vulnerability affects versions prior to 8.3.8 and can be exploited via the network attack vector, though user interaction is required. An authenticated attacker with contributor or developer privileges can craft malicious input that executes arbitrary JavaScript in the context of a visitor's browser session, potentially leading to data theft or account compromise. The vulnerability has been patched in version 8.3.8 and later.

Affected products

  • Xtemos WoodMart before 8.3.8

Timeline

  • 2025-12-10: disclosed: Vulnerability reported to Patchstack
  • 2026-09-04: advisory: Published by Patchstack and NVD
  • 2026-09-04: patched: Fixed in version 8.3.8

References

Related threats