Junglewise Threat Intelligence

CVE-2026-77996: YOOtheme Pro stored XSS in location custom field

CVE-2026-77996 · Severity: info · Published 2026-08-25

Vendors: YOOtheme.

Executive brief

YOOtheme Pro is a popular page builder for Joomla and WordPress websites. An authenticated user with sufficient privileges can inject malicious scripts into the location custom field, which are then executed when viewed by other users. This could lead to account takeover, credential theft, or defacement for site administrators and other privileged users.

Technical details

This vulnerability is a stored cross-site scripting (XSS) flaw in the location custom field of YOOtheme Pro versions 1.0.0 through 5.0.41. The root cause is a lack of proper output escaping when rendering the location field. An authenticated attacker with privileged access (such as a site editor or administrator) can inject malicious JavaScript into the field; the script is stored in the database and executed in the browsers of other users who view the affected page or content. Exploitation requires authentication and elevated privileges. The vulnerability allows for session hijacking, credential harvesting, administrative action execution, or site defacement.

Affected products

  • YOOtheme YOOtheme Pro 1.0.0-5.0.41

Timeline

  • 2026-08-25: disclosed

References