Junglewise Threat Intelligence

CVE-2026-39548: Sneeit MagOne Reflected XSS in WordPress theme

CVE-2026-39548 · Severity: high · CVSS 7.1 · Published 2026-06-17

Executive brief

MagOne, a popular WordPress theme used for news and magazine-style websites, contains a security vulnerability that allows attackers to inject malicious scripts. By tricking a user into clicking a specially crafted link, an attacker can execute code in the user's browser, potentially leading to unauthorized actions, theft of session information, or website defacement. This issue affects all versions up to and including 9.0.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sneeit MagOne theme for WordPress (versions <= 9.0) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject malicious JavaScript into the victim's browser session. Exploitation requires a victim to interact with a malicious link (User Interaction: Required). Successful exploitation can lead to session hijacking, unauthorized administrative actions if the victim is an administrator, or redirection to malicious sites. The issue is resolved in version 9.1.

Affected products

  • Sneeit MagOne <= 9.0

Timeline

  • 2026-02-07: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-04-16: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date
  • 2026-06-17: patched: Patch confirmed available in version 9.1

References