Junglewise Threat Intelligence

CVE-2026-8167: THEWP Digital Solutions News Theme V8 reflected XSS

CVE-2026-8167 · Severity: medium · CVSS 6.1 · Published 2026-07-28

Executive brief

A security vulnerability exists in the News Theme V8 website template by THEWP Digital Solutions. This flaw allows attackers to inject malicious scripts into the web pages viewed by other users. If exploited, this could lead to unauthorized actions being performed in a user's browser, such as stealing session information or redirecting visitors to malicious websites.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in THEWP Digital Solutions News Theme V8 through version 16.06.2026. The vulnerability stems from the application's failure to properly sanitize or neutralize user-supplied input before including it in dynamically generated web pages (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access.

Affected products

  • THEWP Digital Solutions News Theme V8 through 16.06.2026

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory

References