Junglewise Threat Intelligence

CVE-2026-56072: Xtemos WoodMart unauthenticated XSS

CVE-2026-56072 · Severity: high · CVSS 7.1 · Published 2026-06-26

Executive brief

WoodMart, a popular premium e-commerce theme for WordPress, contains a security vulnerability that allows unauthorized attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially hijack user sessions, redirect customers to fraudulent websites, or deface the online store. This issue affects the security and integrity of the shopping experience and could lead to unauthorized access to site management tools.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Xtemos WoodMart theme for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to craft a malicious payload that, when executed in a victim's browser (typically requiring some user interaction like clicking a link), can access sensitive information such as session cookies or perform actions on behalf of the user. The vulnerability is present in versions up to and including 8.5.3. A patch is available in version 8.5.4.

Affected products

  • Xtemos WoodMart <= 8.5.3

Timeline

  • 2026-06-12: other: Reported by researcher daroo
  • 2026-06-25: advisory: Patchstack advisory published
  • 2026-06-26: disclosed: NVD publication date
  • 2026-06-25: patched: Version 8.5.4 released to address the issue

References

Related threats